Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Apr 20, 2012 | Updated Sep 15, 2017

TrojanSpy:Win32/Bafi.Q

Detected by Microsoft Defender Antivirus

Aliases: TrojanSpy.Banker!pOua17PZ7mI (VirusBuster) Trojan horse PSW.Banker6.UPI (AVG) TR/Spy.Gen (Avira) Win32/Spy.Banker.XSM trojan (ESET) Trojan-PWS.Banker6 (Ikarus) TROJ_SPNR.26DF12 (Trend Micro)

Summary

TrojanSpy:Win32/Banker.VCA is a member of Win32/Banker - a family of data-stealing trojans that captures online banking credentials, such as account login names and passwords, and relays the captured information to a remote attacker. TrojanSpy:Win32/Banker.VCA disguises itself as "Adobe PDF Reader Link Helper" and is registered on the computer as a Browser Helper Object (BHO) that intercepts browser communications.

To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat:

For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.

If you think you have been the victim of this malware and your banking details have been stolen, you can refer to Microsoft's advice on what to do if you are a victim of fraud.

Follow us