Sophos

Troj/Bancban-QB

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from July 2007 (4.19)
Protection available since 30 May 2007 11:36:39 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Bancban-QB is an information-stealing Trojan for the Windows platform.

When first run Troj/Bancban-QB copies itself to <Windows>\Media\w7zip.exe and creates the following files:

<Current folder>\Emails.dat
<Current folder>\Emails.txt
<Windows>\lnk_dados_1.dll

Troj/Bancban-QB creates the following registry entry in order to run itself on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
w7zip
<Windows>\Media\w7zip.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer