Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | February 2006 (4.02) |
| Protection available since | 21 March 2005 23:10:25 (GMT) |
| Last updated | 29 December 2005 23:27:19 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Vipgsm-AB is a Windows Trojan that steals passwords and logs keystrokes and window titles while running in the background as a service process.
Troj/Vipgsm-AB copies itself to the Windows system folder with the filename msgina32.exe and drops helper files itstore.dll and msshell.dll.
The Trojan creates the following registry entries in order to run automatically each time a user logs on:
HKCR\CLSID\(<randomly chosen CLSID>)
InProcServer32\@
msshell.dll
HKLM\Software\Microsoft\Windows\CurrentVersion
ShellServiceObjectDelayLoad\Shell
(<randomly chosen CLSID as set above>)
Troj/Vipgsm-AB also creates the following registry entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Applets
Cd Player.31
The Trojan adds entries to the the HOSTS file (located in '<Windows system folder>\drivers\etc') in order to prevent access to certain security related websites.
Troj/Vipgsm-AB will attempt to periodically send information via HTTP to a predefined web site
