Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | June 2005 (3.94) |
| Protection available since | 14 April 2005 13:25:59 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Banker-CC is a password stealing Trojan for the Windows platform.
Troj/Banker-CC copies itself to the Windows system folder as svchost.scr and creates the following registry entry using the name of the file when executed to ensure it is run at system logon:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
<filename>
%SYSTEM%\svchost.scr
Troj/Banker-CC monitors which URLs are visited by the web browser and creates fake web pages for certain Brazilian banking sites in order to log account information. The logged information is sent to remote users via email.
