AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
January 07, 2009, 03:04:21 PM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 5331 Members
Latest Member: infursify
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Virus Alerts  |  Topic: PWSteal.Flecsip password stealing Trojan Horse 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: PWSteal.Flecsip password stealing Trojan Horse  (Read 294 times)
Brad
SysAdmin
Tech Team
Hero Member
********
Offline Offline

Posts: 391



View Profile
PWSteal.Flecsip password stealing Trojan Horse
« on: July 11, 2005, 11:21:07 PM »

PWSteal.Flecsip is a password stealing Trojan that logs passwords and other confidential data entered by the user accessing Web pages through Internet Explorer. The Trojan saves a log file with stolen data and attempts to send it to a remote attacker.

When PWSteal.Flecsip is executed, it performs the following actions:

   1. Copies itself as %System%\msserv.exe.

      Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).

   2. Adds the value:

      "msserv" = "%System%\msserv.exe"

      to the registry subkey:

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

      so that it runs every time Windows starts.

   3. Monitors active Internet Explorer browser windows. When the user visits a Web site the Trojan logs page data and user text entered and saves it to the following log file:

      %System%\servms.dll

   4. Attempts to send the stolen information to a predetermined email account on the yandex.ru domain.

REMOVAL INSTRUCTIONS
See: http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.flecsip.html

To delete the value from the registry
   1. Click Start > Run.
   2. Type regedit
   3. Click OK.
   4. Navigate to the subkey:

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

   5. In the right pane, delete the value:

      "msserv" = "%System%\msserv.exe"

   6. Exit the Registry Editor.
Logged

Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Virus Alerts  |  Topic: PWSteal.Flecsip password stealing Trojan Horse « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!