Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | October 2005 (3.98) |
| Protection available since | 29 August 2005 14:24:15 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Bancj-A is a password-stealing Trojan for the Windows platform.
Troj/Bancj-A monitors browser activity for visits to specific banking websites. On detecting such activity, the Trojan displays a fake login page and records keystrokes in an attempt to steal login details. Any information stolen in this manner is submitted to the author by email.
When the Trojan is installed it creates the file %SYSTEM%\imgit.txt. This file can be deleted.
The following registry entry is created to run Troj/Bancj-A on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
imgit
