Sophos

Troj/Bancos-DR

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from September 2005 (3.97)
Protection available since 4 August 2005 03:38:52 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Bancos-DR is a password stealing Trojan for the Windows platform.

Troj/Bancos-DR monitors which URLs are typed into a web browser and creates fake webpages for certain Brazilian banking sites in order to log user account information. This information may then be sent to predetermined email addresses.

Troj/Bancos-DR copies itself to the Windows system folder as charmapnt.exe and may set the following registry entry in order to run each time a user logs on:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
<value>
"<Windows system folder>\charmapnt.exe"

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer