Jump to content

Financial Passwords and Credit Card Numbers Stolen


Scarecrow Man
 Share

Recommended Posts

There is more information about the identity theft operation I reported late Saturday.

Patrick Jordan, a researcher for Sunbelt, maker of Counterspy antispyware, made the discovery while investigating a new variant of the CoolWebSearch browser hijacker. After this variant was running on his test machine, Jordan discovered that it had downloaded and installed surveillance spyware.

This as-yet-unidentified spyware logs instant message and other chat activity, the web addresses visited by the victim, user names and passwords the victim uses to log into various web sites, as well as information filled out on web site forms. The spyware also accesses Microsoft's Internet Explorer "Protected Storage", which is where Internet Explorer stores information and passwords entered into web forms.

http://www2.spywareinfo.com/2005/08/08/569

Link to comment
Share on other sites

The spyware also accesses Microsoft's Internet Explorer "Protected Storage", which is where Internet Explorer stores information and passwords entered into web forms.

Would I be okay as I have ticked the IE option "Do not save encrypted files to disk" under Security?

Also as the storage is supposed to be 'protected' then this doesn't say much for the protection! :o

Link to comment
Share on other sites

Would I be okay as I have ticked the IE option "Do not save encrypted files to disk" under Security?

Also as the storage is supposed to be 'protected' then this doesn't say much for the protection!  :o

Don't think your protected just because you've ticked off an option, or use AV software.

According to this article, this variant of CoolWebShreedder is yet unknown.

The only thing you can do right now is check for updates to your AV software, spyware software, and windows daily.

Also, keep an eye on this page for more info.

See nels topic here for info

EDIT: According to spywareinfo, there is a diagnostic and removal utility read here

Also, This new trojan has been dubbed "Srv.SSA-KeyLogger"

Link to comment
Share on other sites

On my Spanish account nothing is stored on the PC, also the final code is put in using an on screen keyboard so it is not possible to copy keyboard digits.

Not true. The On-screen keyboard uses the exact same Key_Hook() event of the Windows API that a regular keyboard does. An On-screen keyboard is abolutely NO safer than a regular one.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy