Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | July 2006 (4.07) |
| Protection available since | 25 May 2006 13:55:31 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Mesoto-B is a Trojan for the Windows platform.
Troj/Mesoto-B attempts to steal passwords and user information related to Microsoft MSN Messenger, and may send stolen information to a remote user via email.
Troj/Mesoto-B may display a fake MSN screen to encourage users to enter their details.
Troj/Mesoto-B sets the following registry entry to run the file msnmsnr.exe on startup, usually a copy of itself:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Msn Messenger
<System>\msnmsnr.exe
Troj/Mesoto-B may download files from remote locations to <System>\wmsip.dll and to C:\windows\system\ExplorerXP.exe.
