SPYWARE_TRAK_MSNSPYMONITOR


 PLATFORM:

Windows 98, ME, NT, 2000, XP, Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Spyware

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes


  TECHNICAL DETAILS

Installation

This spyware adds the following folders:

  • %Program Files%\MSN Spy Monitor
  • %Program Files%\MSN Spy Monitor\images
  • %Program Files%\MSN Spy Monitor\res

(Note: %Program Files% is the default Program Files folder, usually C:\Program Files.)

It drops the following file(s)/component(s):

  • %Program Files%\MSN Spy Monitor\images\box.jpg
  • %Program Files%\MSN Spy Monitor\images\buynow.jpg
  • %Program Files%\MSN Spy Monitor\images\enterkey.jpg
  • %Program Files%\MSN Spy Monitor\images\free.jpg
  • %Program Files%\MSN Spy Monitor\images\icon.jpg
  • %Program Files%\MSN Spy Monitor\images\logo.jpg
  • %Program Files%\MSN Spy Monitor\images\TrusteLogo.gif
  • %Program Files%\MSN Spy Monitor\License.txt
  • %Program Files%\MSN Spy Monitor\MSNSM.exe
  • %Program Files%\MSN Spy Monitor\readme.txt
  • %Program Files%\MSN Spy Monitor\unins000.dat
  • %Program Files%\MSN Spy Monitor\unins000.exe
  • %System%\mfile.emx
  • %System%\regsvcm.exe
  • %System%\windllm.exe

(Note: %Program Files% is the default Program Files folder, usually C:\Program Files.. %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)

Other System Modifications

This spyware adds the following registry entries:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\ CurrentVersion\Run
RegSvcm = "%System%\regsvcm.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\ CurrentVersion\Uninstall\
MSN Spy Monitor_is1
(Default) =  

  SOLUTION

Minimum Scan Engine:

8.900

VSAPI OPR PATTERN File:

0.659.00

VSAPI OPR PATTERN Date:

20 Jun 2008

Step 1

Remove SPYWARE_TRAK_MSNSPYMONITOR by using its own Uninstall option

[ Learn More ]
To uninstall the grayware processDATA_GENERIC
  • Click on Change/Remove.
  • Follow the instructions on the dialog box that appears.
  • Close the Add/Remove Programs window, and the Control Panel window.
  • Step 2

    Scan your computer with your Trend Micro product to delete files detected as


    *Note: If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.


    Did this description help? Tell us how we did.