Sophos

Troj/Bancban-BX

Aliases
  • Trojan-Spy.Win32.Banker.ju
  • PWS-Bancban.gen.b
  • TROJ_BANCBAN.DU
  • Trojan.Bancos-134
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from May 2005 (3.93)
Protection available since 26 March 2005 16:14:32 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Bancban-BX is a Trojan that attempts to steal banking details, in particular those for accounts related to Banco Do Brasil.

Troj/Bancban-BX monitors information entered into banking websites. Stolen information is sent to a remote user by email.

When first run, the Trojan copies itself to the Windows system folder as SVCHOST.SCR and creates the following registry entry in order to run itself on system logon or startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
c
<Windows system>\svchost.scr

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer