Welcome to the Virus Encyclopedia of Panda Security.
It obtains confidential information about the user, such as passwords stored in Internet Explorer, Outlook and MSN Messenger, and about the affected computer, such as version of the operating system, username and IP address. It spreads via IRC channels.
|First detected on:||May 20, 2009|
|Detection updated on:||June 22, 2009|
|Yes, using TruPrevent Technologies
PasswordStealer.BM is a worm which obtains confidential information about the user, such as passwords stored in Internet Explorer, and about the computer, such as version of the operating system, username and IP address. Then, it sends the gathered information to its creator via IRC.
PasswordStealer.BM spreads via IRC by sending a compressed copy of itself to all the users connected to the same channel as the affected user.
PasswordStealer.BM is easy to recognize, as it displays the following symptoms:
- When it is run, it displays the following window:
- It modifies the Internet Explorer start page, changing it to the following: