Other versions: Trojan-PSW.Win32.Coced, .215, .219, .220
Trojan-PSW.Win32.Coced.219.b (Kaspersky Lab)
is also known as:
Trojan.PSW.Coced.219.b (Kaspersky Lab),
IRC/Pws.gen (McAfee), Trojan Horse (Symantec), Trojan.PWS.Coced.219 (Doctor Web), Troj/Rek (Sophos), PWS:Win32/Coced.2_19.B (RAV), TROJ_STEALTH.D (Trend Micro), TR/Coced-219 (H+BEDV), W32/Backdoor.Stealth (FRISK), Win32:Trojan-gen. (ALWIL), Trojan.PSW.Coced.219.B (SOFTWIN), Trojan.PSW.Coced.219.B (ClamAV), Trj/Coced.219 (Panda), Win32/PSW.Coced.219.B (Eset)
This Trojan is one of a family of Trojans which steals user passwords. It
is designed to steal confidential data. It is a Windows PE EXE file. The file
is 208,901 bytes in size. It is written in Visual C++.
Installation
Once launched, the Trojan copies its executable file to the Windows system
directory:
%System%\msrun.exe
The Trojan also extracts the following file from its body (this file is 197,634
bytes in size):
%Temp%\Winvrfy.exe
The Trojan changes the values of the following system registry keys:
[HKCU\Software\Mirabilis\ICQ\Agent\Apps\ICQ]
"Enable" = "yes"
"Path" = "<path to Trojan executable file>"
"Startup" = ""
"Parameters" = ""
[HKCU\Software\Mirabilis\ICQ\Agent]
"Launch Warning" = "No"
The Trojan harvests the paramenter values of the following registry sub-key:
[HKCU\Software\Mirabilis\ICQ\Owners]
The Trojan also harvests information about modem connections used by the system
to access the Internet. It also harvests passwords using WNetEnumCachedPasswords).
The Trojan sends harvested data to ***ihvseh@iname.com, the remote malicious user's email address. The Trojan uses mail.computer.com
to send outgoing messages.
If your computer does not have an up-to-date antivirus, or does not have an
antivirus solution at all, follow the instructions below to delete the malicious
program:
- Use Task Manager to terminate the Trojan process.
- Delete the original Trojan file (the location will depend on
how the program originally penetrated the victim machine).
- Delete the following system registry key parameters:
[HKCU\Software\Mirabilis\ICQ\Agent\Apps\ICQ]
"Enable" = "yes"
"Path" = "<path to Trojan executable file>"
"Startup" = ""
"Parameters" = ""
[HKCU\Software\Mirabilis\ICQ\Agent]
"Launch Warning" = "No"
- Delete all files created by the Trojan:
%Temp%\Winvrfy.exe
%System%\msrun.exe
- Update your antivirus databases and perform a full scan of the
computer (download a trial version of Kaspersky Anti-Virus).