Sophos

Troj/Vipgsm-AB

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from February 2006 (4.02)
Protection available since 21 March 2005 23:10:25 (GMT)
Last updated 29 December 2005 23:27:19 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Vipgsm-AB is a Windows Trojan that steals passwords and logs keystrokes and window titles while running in the background as a service process.

Troj/Vipgsm-AB copies itself to the Windows system folder with the filename msgina32.exe and drops helper files itstore.dll and msshell.dll.

The Trojan creates the following registry entries in order to run automatically each time a user logs on:

HKCR\CLSID\(<randomly chosen CLSID>)
InProcServer32\@
msshell.dll

HKLM\Software\Microsoft\Windows\CurrentVersion
ShellServiceObjectDelayLoad\Shell
(<randomly chosen CLSID as set above>)

Troj/Vipgsm-AB also creates the following registry entry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Applets
Cd Player.31

The Trojan adds entries to the the HOSTS file (located in '<Windows system folder>\drivers\etc') in order to prevent access to certain security related websites.

Troj/Vipgsm-AB will attempt to periodically send information via HTTP to a predefined web site

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer