SHARE
THIS ON

Facebook Twitter Google Plus

Trojan.PWS.OnlineGames.ZAY

MEDIUM
MEDIUM
~49KB unpacked
()

Symptoms

Presence of woooooo.dll file in %SYSTEM% directory.
Presence of AppInit_DLLs with data woooooo.dll in HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows registry key.
Increased network activity.

Removal instructions:

Please let BitDefender delete your files.

Analyzed By

Marius TIVADAR, virus researcher

Technical Description:

This trojan is intended to steal passwords from online games. Once it is executed, a .dll file will be dropped in %SYSTEM% directory. That .dll file actually does all the job.

On a new system restart, the dll will be injected in every running process. If the target process is not the right one, the trojan will simply unload itself from that process.

Next, this malware will do several things to break the application protection, and then will send stolen data to a web server, originated in China. While communicating with server, User-Agent is set to "Inet".

Malware communicates with server using GET method, link looks something like:
http://sy62[removed]22.org/chuanshi/push.asp?b=..&k=..