Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | December 2005 (4.00) |
| Protection available since | 26 October 2005 13:21:40 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Bancban-GQ is a password stealing Trojan for the Windows platform.
Troj/Bancban-GQ targets customers of certain Brazilian online banking websites by displaying fake interfaces, and recording any details that are entered.
When first run, Troj/Bancban-GQ copies itelf to <Windows>\wupdmgr.exe, and creates the following registry entry to ensure that it is run when an infected system starts:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Windows Update
<Windows>\wupdmgr.exe
