mAliCious Code 225
within a Web browser. Websites use forms for a user to enter logon
credentials. Form-grabbing spyware minimizes the amount of infor-
mation gathered by stealing data only included in these forms.
29
For
example, the prolific Zeus banking Trojan steals a user’s online bank-
ing credentials by monitoring his or her Web browser and capturing
usernames and passwords used to log onto banking websites.
Another specific method to steal credentials and sensitive data
from a system includes retrieving stored usernames and passwords
from Windows Protected Storage (WPS). WPS is a location in the
Windows registry that holds auto-complete data and saved passwords
for Internet Explorer, Outlook, and MSN Messenger. Spyware can
access t