Sophos

Troj/Bancban-EJ

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from October 2005 (3.98)
Protection available since 15 August 2005 16:56:18 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Bancban-EJ is a Trojan for the Windows platform, which monitors web access.
When the user visits certain banking websites, Troj/Bancban-EJ displays a fake login screen in order to steal account information.

The Trojan can then email the stolen information to a remote user.

When first run Troj/Bancban-EJ copies itself to <System>\NeroLoader.exe.

The following registry entry is created to run NeroLoader.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
NeroLoader
<System>\NeroLoader.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer