Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Included in our products from | June 2008 (4.30) |
| Protection available since | 6 May 2008 15:11:32 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Banker-ELN attempts to redirect connections to a banking website to a spoof site.
Troj/Banker-ELN modifies the file <System>\drivers\etc\hosts, redirecting connections to the following web addresses to a fixed IP address:
www.banamex.com
banamex.com.mx
bancanetempresarial.banamex.com.mx
boveda.banamex.com
www.banamex.com.mx
www.bancanetempresarial.banamex.com.mx
www.boveda.banamex.com
The Trojan then opens the spoof site in the default browser.
