For Consumer

Virus Profile: pwszbot-fpk!76a8c7949949

Threat Search
Print
   
Virus Profile information details
Risk Assessment: Home Low | Corporate Low
Date Discovered: 1/26/2014
Date Added: 1/26/2014
Origin: Unknown
Length: Varies
Type: Hoax
Subtype: Win32
DAT Required: 7324
   
 
   

Virus Characteristics

“pwszbot-fpk!76a8c7949949” is a detection for a Trojan that steals sensitive information from the compromised machine and sends it to the remote attacker.

“pwszbot-fpk!76a8c7949949” is a detection for a Trojan that steals Victim's email messages using legitimate MAPI(Messaging Application Programming Interface) code.

“pwszbot-fpk!76a8c7949949” steals stored passwords from following application.

  • Hotmail
  • Microsoft Outlook
  • Outlook Express
Upon execution the Trojan steals information and sends to the following remote server.

  • hxxp: ssshsecu[Removed]ata.php

Trojan steals these credentials by parsing the following registry keys:

  • HKEY_USERS\S-1-5-21-1844237615-1085031214-1417001333-500\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem


  • HKEY_USERS\S-1-5-21-1844237615-1085031214-1417001333-500\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profile


The following registry key values have been added to the system


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109A10090400000000000F01FEC\Usage\OutlookMAPI2Intl_1033: 0x44300002

Trojan uses the above MAPI code for getting folders and messages.

Indication of Infection

Presence of above mentioned activities

Methods of Infection

Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, email spam, etc.

Removal Instructions

Use current engine and DAT files for detection and removal. Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).