Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | December 2005 (4.00) |
| Protection available since | 31 October 2005 21:41:15 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/BankDl-S is a Trojan for the Windows platform.
Troj/BankDl-S sets the following registry entry to run cmsrss.exe on system startup, which is usually a copy of itself:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
cmrss
<Windows system folder>\cmrss.exe
Troj/BankDl-S attempts to download and execute a file from a remote website to the file msbcs.exe in the Windows system folder. At the time of writing the downloaded file is detected by Sophos's anti-virus products as a member of the Troj/Banci-Fam family of banking Trojans.
