Sophos

Troj/Vipgsm-K

Aliases
  • Trojan-PSW.Win32.Vipgsm.as
  • BKDR_VIPGSM.C
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2005 (3.99)
Protection available since 12 October 2005 02:03:06 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Vipgsm-K is a keylogger and password stealing Trojan for the Windows platform.

Troj/Vipgsm-K includes functionality to access the internet and communicate with a remote server via HTTP.

When first run Troj/Vipgsm-K copies itself to <System>\mstcpmon.exe and creates the following files:

<System>\chkdskw.exe
<System>\itstore.dll
<System>\karnal32.dll
<System>\mslogon.dll
<System>\mswshell.dll

These files are all detected as Troj/Vipgsm-K.

The following registry entries are created to run code exported by <System>\mswshell.dll on startup:

HKCR\CLSID\(random GUID)\InProcServer32
(default)
"mswshell.dll"

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\
ShellServiceObjectDelayLoad\
Shell
"(random GUID)"

The following line is added to the [chkdsk] section of Win.ini to run chkdsk on startup:
checked = 1

The infected computer's hosts file is also modified so as to deny access to security related websites.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer