Trojan.PWS.Pogle.3
(TROJ_POGLE.A, Trojan-PSW.Win32.Agent.lr, TR/PSW.Agent.LR, Generic_c.FKD, Trojan.Delf.LP, PWS:Win32/Lmir, Generic PWS.y, TROJ_Generic, W32/PWStealer.BJR, Trojan-PSW.Win32.Delf.lp, TR/Crypt.ASPM.Gen, TR/PSW.LdPinch.bpn, Embedded.Trojan.PWS.LDPinch.1541)
Virus description added:
2007-03-05
Virus type: Trojan program
Affected OS: Win9x/NT/2000/XP/2003
Size: 1 232 896
Packed by: PECOMPACT, Armadillo, ASProtect
Technical information
Written with Delphi
Distributes as QIP Password Reminder v1.6 program
Being started by a careless user, malware copies itself in %WinDir%\system as syshost.exe. This copy is registered into autorun section of system registry:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
syshost = "C:\WINDOWS\system\syshost.exe"
Also it creates and starts such files: icqpc2.exe (193 536 bytes)and p11.exe (157 184 bytes), which are detected by Dr.Web(R) anti-virus as Trojan.PWS.Pogle.3 and Trojan.PWS.LDPinch.1541 relatively.
As a result, registered passwords will be sent to the malefactor.
System Recovery Information
1. Load Windows OS in Safe Mode (F8 as Windows starts).
2. Use either disc scanner Dr.Web® or free Dr.Web® CureIT! utility to scan computer local discs. Apply “Cure” to all infected files, which have been detected.
3. Recover registry from backup copy.
4. Attention! All registered passwords should be changed throughout system.