Sophos

Troj/Bancos-RS

Aliases
  • Trojan-Spy.Win32.Bancos.ha
  • PWSteal.Bancos
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 14 March 2006 11:05:39 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

Troj/Bancos-RS is a banking Trojan for the Windows platform.

Troj/Bancos-RS targets the users of several Brazilian banks by monitoring the user's internet activity and displaying fake login pages if the user visits certain predefined URLs. Any login details entered on the fake pages are logged.

Troj/Bancos-RS contains the functionality to email these logged details to a remote user.

When first run Troj/Bancos-RS copies itself to <Windows>\kernels32.exe.

The following registry entries are created to run kernels32.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Service System
<Windows>\kernels32.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Run
Service System
<Windows>\kernels32.exe

Troj/Bancos-RS may attempt to access the internet and download a file from a remote server via HTTP.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer