Threat Search: 

ThreatExpert's Statistics for Dropper/MailPass.632320 [AhnLab]:

Dropper/MailPass.632320 [AhnLab] is also known as:
Threat AliasNumber of Incidents
Mal/Banspy-F [Sophos]88
Infostealer [Symantec]80
not-a-virus:PSWTool.Win32.MailPassView.ck [Kaspersky Lab]72
Trojan-PSW.Generic [PC Tools]56
Trojan-Banker.Win32.Banker [Ikarus]8
Trojan-PWS.Win32.Delf [Ikarus]8

Dropper/MailPass.632320 [AhnLab] has the following possible countries of origin:
OriginNumber of Incidents
Brazil48
Israel48

Dropper/MailPass.632320 [AhnLab] is known to be created as:
%System%\msnwabs.exe
%Windir%\msagent\msnwab.exe
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.