Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | June 2005 (3.94) |
| Protection available since | 18 April 2005 05:35:10 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Banker-CG is a password-stealing Trojan for the Windows platform.
Troj/Banker-CG monitors browser activity for visits to specific banking websites. On detecting such activity, the Trojan displays a fake login page and records keystrokes in an attempt to steal login details.
Any information stolen in this manner is submitted to the author by email.
When the Trojan is installed it creates the file %SYSTEM%\imgit.txt.
The following registry entry is created to run Troj/Banker-CG on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
imgit
<pathname of the Trojan executable>
