Virus name (in Chinese):
Virus alias:
Threat Level: ★☆☆☆☆
Virus type: Trojan Horse program
Virus Length: 43520
Impact System: WIN9X/WINM/EWINNT/WIN2000/WINXP/WIN2003
Virus behavior:
This is a theft of legendary account and password Trojan horse program.
The virus shuts down security software, installs message hooks, automatically hooks all windows, and, if it is a legendary game window, records account numbers and passwords, which are sent to a designated mailbox via the SMTP engine that came with it.
1, release the following documents:
C:\rundll32.exe
C:\WINNT\System32\cq3dll.dll
2, modify the registry key:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"LoadMecq3" = "C:\rundll32.exe"
To achieve the purpose of starting.
3, turn off the following security software:
Kvxp. Kxp
Kvmonxp.kxp
4, install message hooks, hook all windows, find legendary game window, record account and password information, save to the following path:
C:\gamecq3.txt
5, build the SMTP engine and send the C:\gamecq3.txt to the specified mailbox.