Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | July 2006 (4.07) |
| Protection available since | 12 May 2006 20:21:13 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Banker-BIR is a password-stealing Trojan for the Windows platform.
Troj/Banker-BIR includes functionality to send notification messages to remote locations.
When first run Troj/Banker-BIR copies itself to:
<Startup>\help.scr
<Windows system folder>\help.scr
and creates the file <CurrentFolder>\iphist.dat.
The following registry entry is created to run help.scr on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
help
<Windows system folder>\help.scr
