Kaspersky Laboratory recently detected a game against the "underground city and the Warriors," the Theft of Trojan Horse (Trojan.Win32.Vilsel.ah) infection rate has increased, resulting in a large number of netizens account stolen, more harmful. The Trojan is not shell, generally through the web page hanging horse or download device to download and other means of infection. After infection, it releases the malicious files to the computer and shuts down the Windows File Protection feature, replacing the malicious DLL files it releases from the system's normal files. The trojan DLL is then injected into all processes. Trojan DLL will automatically search and close the Tencent game landing process QQLogin.exe, and opportunistic use of the message hook to steal user account password. Not only this, this trojan also intercepts the user's screen, obtains the secret security, and will wait for these to steal to each kind of information to send to the remote host, causes the economic loss and the privacy leakage to the infected user.
At present, Kaspersky has been able to successfully killing the "underground City and Warriors" stolen Trojan Horse, we recommend that you update the virus database as soon as possible to avoid unnecessary losses.