"Fantasy stealing" (Win32.PSWTroj. OnlineGames.14848) is a trojan virus that mainly steals the account and password of "Fantasy westward journey. "Ad downloader" (Win32.Adware. Navi.394615) is an advertisement virus.
I. Threat Level:★
This virus is mainly used to steal account information of "Fantasy westward journey.
1. The "LYMANGR. dll" file generated by the virus will enumerate the processes on the client's computer and find my.exe, the process of the online game "Fantasy westward journey. Enumerate the modules of the process. If no other file MSDEG32.dll is found, inject the virus file into my.exe by writing the memory.
2. Create a socket on the client computer and bind it to "2*2.1*9.2*4.1*3 ".
3. The specified receiving URL:
Hxxp: // www. 5151la. com/mh2007/post2007kj. asp /? Server = xx & gameid = xx & pass = xx & pin = xx & wupin = xx & role = xx & equ = cash: xx deposit: xx & other = Build: xx
Hxxp: // www. raceswd. com/cs03/post. asp /? Server = xx & gameid = xx & pass = xx & pin = xx & wupin = xx & role = xx & equ = cash: xx deposit: xx & other = Build: xx
[Content navigation] |
Page 1: The leeching of dreams |
Page 1: Ad downloader |
Page 3rd: suggestions from anti-virus engineers |
|