AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
January 07, 2009, 04:51:45 PM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 5335 Members
Latest Member: Addiguiva
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Virus Alerts  |  Topic: PWSteal.Omerstroke 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: PWSteal.Omerstroke  (Read 302 times)
Brad
SysAdmin
Tech Team
Hero Member
********
Offline Offline

Posts: 391



View Profile
PWSteal.Omerstroke
« on: July 22, 2005, 07:50:20 PM »

PWSteal.Omerstroke is a Trojan horse that monitors the AOL interface and emails passwords to a predetermined address. It also monitors open IM windows in the AOL interface and may send the captured IM messages to a predetermined AOL chatroom

When PWSteal.Omerstroke is executed, it performs the following actions:

   1. Displays a fake error message. The message has the following characteristics:

      Title: Windows
      Body: File not found: 'COMCTLDG32.OCX'

   2. Attempts to copy the file %CurrentFolder%\newestpics.exe as:

      C:\Windows\system\mstasks.exe

      Note: %CurrentFolder% is a variable that refers to the folder where the risk was originally executed.

   3. Adds the value:

      "mstasks" = "c:\windows\system\mstasks.exe -quiet"

      to the registry subkey:

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

      so that it runs every time Windows starts.

   4. Monitors the AOL interface. If the user changes the AOL password, the Ttrojan sends an email containing the new password to a predetermined email address on the elitemail.org domain.

   5. Monitors the open IM windows within the AOL interface and may send captured IM messages to a predetermined AOL chatroom.

REMOVAL INSTRUCTIONS
See: http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.omerstroke.html

To delete the value from the registry   
   1. Click Start > Run.
   2. Type regedit
   3. Click OK.
   4. Navigate to the subkey:

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

   5. In the right pane, delete the value:

      "mstasks" = "c:\windows\system\mstasks.exe -quiet"

   6. Exit the Registry Editor.
Logged

Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Virus Alerts  |  Topic: PWSteal.Omerstroke « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!