Sophos

Troj/Bancban-BY

Aliases
  • Trojan-Spy.Win32.Banker.ea
  • BackDoor-CHC
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from May 2005 (3.93)
Protection available since 27 March 2005 04:23:08 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Bancban-BY is a Trojan that attempts to steal banking details for certain Brazilian banks.

Troj/Bancban-BY monitors information entered into banking websites. Stolen information is sent to a remote user by email. The Trojan may display a fake user interface in order to trick the user into entering confidential details.

The Trojan creates the following registry entry in order to run itself on system logon or startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
winreg_32
<path to Trojan>

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer