Behavior
Hacktool.WinSniffer monitors incoming and outgoing network traffic and decodes FTP, POP3, HTTP, ICQ, SMTP, Telnet, IMAP, and NNTP usernames and passwords.
Symptoms
One or more files are detected as Hacktool.WinSniffer.
Transmission
This program must be manually installed.
technical details
File names: WSMDI.exe
Hacktool.WinSniffer monitors incoming and outgoing network traffic and decodes FTP, POP3, HTTP, ICQ, SMTP, Telnet, IMAP, and NNTP usernames and passwords.
1. The installer for Hacktool.WinSniffer creates the following clean files:
* %UserProfile%\Start Menu\Win Sniffer\Win Sniffer 1.22.lnk
* %UserProfile%\Start Menu\Win Sniffer\Win Sniffer Help.lnk
* %ProgramFiles%\WinSniffer\Ctl3dv2.dll
* %ProgramFiles%\WinSniffer\Inetwh16.dll
* %ProgramFiles%\WinSniffer\INETWH32.dll
* %ProgramFiles%\WinSniffer\INSTALL.LOG
* %ProgramFiles%\WinSniffer\msvcrt.dll
* %ProgramFiles%\WinSniffer\msvcrt.dll\mfc42.dll
* %ProgramFiles%\WinSniffer\Pcandis3.vxd
* %ProgramFiles%\WinSniffer\Pcandis4.sys
* %ProgramFiles%\WinSniffer\Pcandis5.sys
* %ProgramFiles%\WinSniffer\Setbrows.exe
* %ProgramFiles%\WinSniffer\UNWISE.EXE
* %ProgramFiles%\WinSniffer\W32N50.dll
* %ProgramFiles%\WinSniffer\ws.ico
* %ProgramFiles%\WinSniffer\WSMDI.cnt
* %ProgramFiles%\WinSniffer\Wsmdi.hlp
Notes:
* %UserProfile% is a variable that refers to the current user's profile folder. By default, this is C:\Documents and Settings\<Current User> (Windows NT/2000/XP).
* %ProgramFiles% is a variable that refers to the ProgramFiles folder. By default, this is C:\ProgramFiles.
2. Creates the following file, which is the Hacktool.WinSniffer main program:
%ProgramFiles%\WinSniffer\WSMDI.exe
3. Adds the values:
"DisplayName" = "Win Sniffer 1.2"
"UninstallString" = "%ProgramFiles%\WINSNI~1\UNWISE.EXE %ProgramFiles%\WINSNI~1\INSTALL.LOG"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Win Sniffer 1.2
REMOVAL INSTRUCTIONSSee:
http://securityresponse.symantec.com/avcenter/venc/data/hacktool.winsniffer.html