SANS is reporting (nice writeup) instances of a new IE malware app, which captures passwords for banking sites (among other things) before they are encrypted with SSL. Scary. Doesn't seem as if any South African banks are in the watch-list yet, but that's not really the point. The app installs as a BHO (browser helper object) in IE.
SANS also pointed out the brilliant (free) tool BHODemon which lists BHOs installed on your system, and allows you to selectively disable/enable them. Nice and simple.
Leave a comment