Sophos

Troj/Jginko-A

Aliases
  • PWSteal.JGinko
  • PWS-Jginko
  • TSPY_BANCOS.ANM
  • Trojan-Spy.Win32.Banker.vt
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from May 2006 (4.05)
Protection available since 12 July 2005 20:42:33 (GMT)
Last updated 27 March 2006 04:43:04 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Jginko-A is a password stealing Trojan targeted at users of Japanese banking websites.

Troj/Jginko-A includes functionality to access the internet and communicate with a remote server via HTTP.

When first run Troj/Jginko-A copies itself to C:\system.exe.

The following registry entry is created to run system.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
system.exe
C:\system.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer