Virus:Trojan-PSW.Win32.Coced.219.bOther versions: .215 , .219 , .220
This Trojan is one of a family of Trojans which steals user passwords. It is designed to steal confidential data. It is a Windows PE EXE file. The file is 208,901 bytes in size. It is written in Visual C++. InstallationOnce launched, the Trojan copies its executable file to the Windows system directory: %System%\msrun.exeThe Trojan also extracts the following file from its body (this file is 197,634 bytes in size): %Temp%\Winvrfy.exe
The Trojan changes the values of the following system registry keys: [HKCU\Software\Mirabilis\ICQ\Agent\Apps\ICQ] [HKCU\Software\Mirabilis\ICQ\Agent] "Launch Warning" = "No" The Trojan harvests the paramenter values of the following registry sub-key: [HKCU\Software\Mirabilis\ICQ\Owners]The Trojan also harvests information about modem connections used by the system to access the Internet. It also harvests passwords using WNetEnumCachedPasswords). The Trojan sends harvested data to ***ihvseh@iname.com , the remote malicious user's email address. The Trojan uses mail.computer.com to send outgoing messages.
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
|
||||||||