Home Malware Programs Trojans PSWTool.MailPassView!sd6

PSWTool.MailPassView!sd6

Posted: December 4, 2009

PSWTool.MailPassView!sd6 is a Trojan that steals private information such as account numbers, passwords and banking credentials. Once installed, PSWTool.MailPassView!sd6 uses the built-in SMTP client engine and communicates with a remote SMTP server to send emails of the collected information to the trojan author. PSWTool.MailPassView!sd6 may also wait in the background and control user's Internet activity. A logging procedure begins when a certain website is accessed, or if the address of a accessed website includes certain words. PSWTool.MailPassView!sd6 may supplement legitimate banking or payment system websites to access user details. PSWTool.MailPassView!sd6 poses a severe security threat to any PC and should be removed immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\winblocsystem.ini
    2 %System%\owner.exe
    3 %System%\systemsn.exe
    4 %System%\systemsn.exe-up.txt
    5 %System%\wuauclt32.dll
    6 c:\%ComputerName%.txt
    7 c:\winxsystem.log
Loading...