Sophos

Troj/Banker-ELO

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from July 2008 (4.31)
Protection available since 8 May 2008 09:45:19 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Banker-ELO is a Trojan which attempts to steal login information related to Brazilian internet banks.

Troj/Banker-ELO copies itself to "<Documents and Settings>\All Users\Start Menu\Programs\Startup\Windows32.exe" in order to run itself on restart.

Troj/Banker-ELO also creates the following registry entry:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Windows32
C:\Arquivos de programas\Windows32.exe

The Trojan may create <Windows>\winload.inf which is an innocuous file and may be simply deleted.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer