Norton AntiVirus Scan resultsTrojan, called Infostealer.Onlinegame
Discovered: January 10, 2008
Updated: January 10, 2008 1:52:32 PM
Type: Trojan
Infection Length: 120,717 bytes
Systems Affected: Windows 98, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000
This Trojan may be downloaded from certain malicious Web sites as the following file:
%CurrentFolder%\2.bat
When it is executed, it creates the following files:
* %Windir%\Help\F3C74E3FA248.dll
* %Windir%\Help\F3C74E3FA248.exe
Next, the Trojan creates the following registry entry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Expl
orer\ShellExecuteHooks\"{1DBD6574-D6D0-4782-94C3-69619E719765}&qu
ot; = ""
It also creates the following registry subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1DBD6574-D6D0-4782-94C3-6
9619E719765}
The Trojan injects itself into the EXPLORER.EXE process.
It then steals sensitive information, such as user names and passwords, related to the following games:
* MapleStory
* World of Warcraft
* MSN Games
* Yahoo Messenger
The Trojan may send this information via email using it own SMTP engine.