Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 12 October 2005 02:03:06 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Vipgsm-K is a keylogger and password stealing Trojan for the Windows platform.
Troj/Vipgsm-K includes functionality to access the internet and communicate with a remote server via HTTP.
When first run Troj/Vipgsm-K copies itself to <System>\mstcpmon.exe and creates the following files:
<System>\chkdskw.exe
<System>\itstore.dll
<System>\karnal32.dll
<System>\mslogon.dll
<System>\mswshell.dll
These files are all detected as Troj/Vipgsm-K.
The following registry entries are created to run code exported by <System>\mswshell.dll on startup:
HKCR\CLSID\(random GUID)\InProcServer32
(default)
"mswshell.dll"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\
ShellServiceObjectDelayLoad\
Shell
"(random GUID)"
The following line is added to the [chkdsk] section of Win.ini to run chkdsk on startup:
checked = 1
The infected computer's hosts file is also modified so as to deny access to security related websites.
