• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

Trojan Horse keylogger steal end-user information for popular online games.

Myantispyware team March 13, 2006    

Websense® Security Labs™ has received reports of a malicious website, which is hosting a Trojan Horse keylogger. This keylogger is designed to steal end-user information for popular online games. The malicious code’s filename is main_n80.scr and was discovered on a site, which appears to be a fraudulent version of the Nokia Taiwan website.
The site uses a cousin domain name and simply has an image screenshot of the real Nokia Taiwan website. It is hosted in Hong Kong and appears to have been registered with fraudulent information.

The main_80.scr file is an SFX self-extracting executable file that contains four files:
* download.exe
* winlogin.exe
* server.exe
* error.jpg
When the main_80.scr file is executed, it will use download.exe to copy the extracted files to the system32 dir and execute its version of run32dll.exe. The rundll32.exe file will show error.jpg. Once the user closes the .jpg file,rundll32.exe will execute the rest of the extracted .exe files.
These extracted .exe files modify the registry, as detailed below, to ensure that it starts on restart, and checks for the existence of the application Lineage.
* Modifies or creates files and stores in system32 directory
* Kerne0110.exe is a copy of winlogin.exe
* Rundll32.exe is a copy of download.exe
* gg.bat is created
* _2dll.dll is created
* microsoftie0110.dll is created
* msabc.dll is created
* pKerme123.dll is created
* RegistryInfo.dll is created

Identity Theft Trojan

 Previous Post

LdPinch again spammed via ICQ

Next Post 

Fake Windows Sites + WMF Explot + Keyloger = New Botnet

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

3 Comments

  1. Steve Lamb's Blog
    ― March 15, 2006 - 10:27 am  Reply

    Evidence of a website that appears to be hosting a malicious keylogger trojan horse

    Trojan horses (software that includes “features” that may work against the user’s intentions) are hardly…

  2. Steve Lamb
    ― March 15, 2006 - 10:28 am  Reply

    Thanks for the interesting website – keep up the good work.

  3. Nursing and some other bits
    ― March 15, 2006 - 3:24 pm  Reply

    Trojan report.

    Just picked up the following warning:
    Websense® Security Labs™ has received reports of a malicious website, which is hosting a Trojan Horse keylogger. This keylogger is designed to steal end-user information for popular online games. The malicious…

Leave a Reply to Steve Lamb Cancel reply

New Guides

scam alert
Remove Searchernow.com Redirect: Chrome, Edge, Firefox
Avoid the ExLig.com Bitcoin Scam: Insights on Promo Code Frauds
scam alert
Denwex.com Review: Bitcoin Promo Codes as a Scam
scam alert
CEFOLEX.com Review: A Closer Look at the Bitcoin Promo Code Scam
The Bigexcoin.com Bitcoin Promo Code Scam: How to Stay Safe

Follow Us

Search

Useful Guides

Managed by your organization chrome virus
Chrome Managed by your organization malware removal guide
Files encrypted by ransomware become useless
How To Recover Encrypted Files (Ransomware file recovery)
remove android virus
How to remove virus from Android phone
browser redirect virus
How to remove Browser redirect virus [Chrome, Firefox, IE, Edge]
How to remove pop-up ads [Chrome, Firefox, IE, Opera, Edge]

Recent Guides

LdPinch again spammed via ICQ
BraveSentry – new rogue anti spyware
Exchange rate conversion tool load Trojan.Downloader and Trojan.Muldrop
Running as Limited User – The Easy Way to keep a system free from malware
Nyxem/Kama Sutra/Blackworm return again

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.