Sophos

Troj/Mesoto-B

Aliases
  • Win32/Spy.Banker.GB
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from July 2006 (4.07)
Protection available since 25 May 2006 13:55:31 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Mesoto-B is a Trojan for the Windows platform.

Troj/Mesoto-B attempts to steal passwords and user information related to Microsoft MSN Messenger, and may send stolen information to a remote user via email.

Troj/Mesoto-B may display a fake MSN screen to encourage users to enter their details.

Troj/Mesoto-B sets the following registry entry to run the file msnmsnr.exe on startup, usually a copy of itself:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Msn Messenger
<System>\msnmsnr.exe

Troj/Mesoto-B may download files from remote locations to <System>\wmsip.dll and to C:\windows\system\ExplorerXP.exe.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer