Sophos

Troj/IBank-C

Aliases
  • TrojanSpy.Win32.Delf.eb
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from December 2004 (3.88)
Protection available since 26 October 2004 09:12:51 (GMT)
Detected by All Sophos products

Action

More Information

Troj/IBank-C is a data stealing Trojan which captures confidential information and then sends it to a remote location.

In particular, Troj/IBank-C will typically try to steal logon information for www.paypal.com.

When web pages are loaded with a location at www.paypal.com, Troj/IBank-C tries to capture text entered into the 'Email Address' and 'Password' text boxes.

When first run Troj/IBank-C moves itself to the Windows system folder, copies itself to the system folder as mswinpid32.exe and creates the following registry entry to run mswinpid32.exe on startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Mswinpid32 = %SYSTEM%\mswinpid32.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer