Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 21 March 2005 23:10:25 (GMT) |
| Last updated | 29 December 2005 23:27:19 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Vipgsm-AB is a Windows Trojan that steals passwords and logs keystrokes and window titles while running in the background as a service process.
Troj/Vipgsm-AB copies itself to the Windows system folder with the filename msgina32.exe and drops helper files itstore.dll and msshell.dll.
The Trojan creates the following registry entries in order to run automatically each time a user logs on:
HKCR\CLSID\(<randomly chosen CLSID>)
InProcServer32\@
msshell.dll
HKLM\Software\Microsoft\Windows\CurrentVersion
ShellServiceObjectDelayLoad\Shell
(<randomly chosen CLSID as set above>)
Troj/Vipgsm-AB also creates the following registry entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Applets
Cd Player.31
The Trojan adds entries to the the HOSTS file (located in '<Windows system folder>\drivers\etc') in order to prevent access to certain security related websites.
Troj/Vipgsm-AB will attempt to periodically send information via HTTP to a predefined web site
