SPYWARE_TRAK_MSNSPYMONITOR
Windows 98, ME, NT, 2000, XP, Server 2003

Threat Type: Spyware
Destructiveness: No
Encrypted:
In the wild: Yes
TECHNICAL DETAILS
Installation
This spyware adds the following folders:
- %Program Files%\MSN Spy Monitor
- %Program Files%\MSN Spy Monitor\images
- %Program Files%\MSN Spy Monitor\res
(Note: %Program Files% is the default Program Files folder, usually C:\Program Files.)
It drops the following file(s)/component(s):
- %Program Files%\MSN Spy Monitor\images\box.jpg
- %Program Files%\MSN Spy Monitor\images\buynow.jpg
- %Program Files%\MSN Spy Monitor\images\enterkey.jpg
- %Program Files%\MSN Spy Monitor\images\free.jpg
- %Program Files%\MSN Spy Monitor\images\icon.jpg
- %Program Files%\MSN Spy Monitor\images\logo.jpg
- %Program Files%\MSN Spy Monitor\images\TrusteLogo.gif
- %Program Files%\MSN Spy Monitor\License.txt
- %Program Files%\MSN Spy Monitor\MSNSM.exe
- %Program Files%\MSN Spy Monitor\readme.txt
- %Program Files%\MSN Spy Monitor\unins000.dat
- %Program Files%\MSN Spy Monitor\unins000.exe
- %System%\mfile.emx
- %System%\regsvcm.exe
- %System%\windllm.exe
(Note: %Program Files% is the default Program Files folder, usually C:\Program Files.. %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
Other System Modifications
This spyware adds the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\ CurrentVersion\Run
RegSvcm = "%System%\regsvcm.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\ CurrentVersion\Uninstall\
MSN Spy Monitor_is1
(Default) =
SOLUTION
Step 1
Remove SPYWARE_TRAK_MSNSPYMONITOR by using its own Uninstall option
Step 2
Scan your computer with your Trend Micro product to delete files detected as
*Note: If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.
Did this description help? Tell us how we did.