Home / malwarePDF  

HackTool:Win32/BrowserPassview


First posted on 21 May 2014.
Source: Microsoft

Aliases :

There are no other names known for HackTool:Win32/BrowserPassview.

Explanation :

Threat behavior

This is a tool that is used to retrieve passwords stored in your web browser's cache.

The tool shows your user names and passwords for websites that you have saved in Internet Explorer, Firefox, Chrome, Opera, Safari and Sea Monkey:





The tool can also be run in hidden mode and can put the passwords it finds into a text file.

We have seen the following malware use this tool to steal passwords:

  • Backdoor:Win32/Fynloski.A
  • PWS:MSIL/Petun.A
  • Trojan:Win32/Sercgov.A
  • TrojanSpy:MSIL/Golroted.A
  • VirTool:Win32/VBInject
  • VirTool:Win32/VBInject.RT
  • VirTool:Win32/VBInject.gen!BP




Analysis by Mihai Calota

SymptomsThe following could indicate that you have this threat on your PC:
  • You have the tool "WebBrowserPassView" installed on your PC

Last update 21 May 2014

 

TOP