|
|
|
VIRUS NAME
: PWS-MSNSteal
Trojan
Characteristics
This is an
MSN Messenger password stealer trojan. It was coded in Visual Basic 6, and requires
MSVBVM60.DLL in order to run.
The internal name of this Trojan is "DONT CLICK.exe". The file icon
of this Trojan is misleading, and becomes even more unobtrusive on default installations
of Windows, where extensions of known file types can be hidden.
Symptoms
Presence of "DONT
CLICK.exe" on the infected host
MSN Messenger becomes unresponsive
Method
Of Infection
This Trojan may pose as a picture as evident by its misleading file icon.
If this Trojan is run on a host system, it will attempt to run a hidden window
of MSMSGS.EXE, MSN Messenger, and then run in Windows memory. It may display
a fake error message like this one: "IMAGING"
The logon credentials of MSN Messenger will then be sent to the author of the
Trojan.
|
|
|