English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Trojan-GameThief.Win32.Nilage.ha

Detected Jun 05 2005 09:57 GMT
Released Jun 05 2005 11:47 GMT
Published Aug 09 2005 12:27 GMT

Technical Details

This Trojan belongs to a family of programs designed to steal system passwords. It steals confidential data about the victim machine, including passwords and information entered via the keyboard.

The Trojan itself is a Windows PE EXE file approximately 68KB in size, packed using ASPack. The unpacked file is approximately 81KB in size.

Installation

When installing, the Trojan copies itself to %Program Files% under one of the names listed below:

%Program Files%\Internat.exe 
%Program Files%\rundll32.exe 
%Program Files%\svhost32.exe 

It then registers this file in the system registry, ensuring that the Trojan file will be launched each time Windows is rebooted on the victim machine.

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"load" = "%Program Files%\svhost32.exe"

The Trojan also creates the following file in the Windows system directory:

%System%\T1dll.dll

Payload

The Trojan harvests a variety of confidential data from the victim machine, including system passwords, keystrokes, and a list of processes launched. This information is then sent to the remote malicious user by email.

Lineage.ha terminates processes where the names contain the following text strings:

Eghost.exe
Iparmor.exe
Kavpfw.exe
Mailmon.exe
Ravmon.exe

Bookmark and Share
Share
Trojan-GameThief

This type of malicious program is designed to steal user account information for online games. The data is then transmitted to the malicious user controlling the Trojan. Email, FTP, the web (including data in a request), or other methods may be used to transit the stolen data.


Other versions

Aliases

Trojan-GameThief.Win32.Nilage.ha (Kaspersky Lab) is also known as:

  • Trojan-PSW.Win32.Nilage.ha (Kaspersky Lab)
  • Trojan-PSW.Win32.Lineage.ha (Kaspersky Lab)
  • Trojan: PWS-Lineage.dll (McAfee)
  • Troj/CodeApp-C (Sophos)
  • Troj/Lineage-AP (Sophos)
  • Trojan.Spy.Lineage-10 (ClamAV)
  • Trojan.Delf-1218 (ClamAV)
  • Trj/Lineage.KD (Panda)
  • Exploit/CodeBase.AT (Panda)
  • W32/Lineage.LP@pws (FPROT)
  • W32/LineageX.BIW (FPROT)
  • PWS:Win32/Lineage (MS(OneCare))
  • Exploit.CodeBase (DrWeb)
  • Trojan.PWS.Lineage (DrWeb)
  • multiple threats (Nod32)
  • Win32/TrojanDownloader.Small.AAO trojan (Nod32)
  • Win32/PSW.Lineage.DN trojan (Nod32)
  • Trojan.Html.Gamect.A (BitDef7)
  • Trojan.PWS.Lineage.HA (BitDef7)
  • Trojan.Crypt.Delf.AP (BitDef7)
  • Trojan.PWS.Nilage.Gen.3 (VirusBuster)
  • HTML:Malware-gen (AVAST)
  • Win32:Trojan-gen (AVAST)
  • Trojan-PWS.Win32.Delf (Ikarus)
  • Exploit.HTML.CodeBaseExec (Ikarus)
  • Trojan-GameThief.Win32.Nilage (Ikarus)
  • PSW.Generic3.QFL (AVG)
  • PSW.Generic.HA (AVG)
  • PSW.Generic2.JJD (AVG)
  • TR/Dldr.Delphi.Gen (AVIRA)
  • /#.eXe <<< TR/Dldr.Delphi.Gen (AVIRA)
  • TR/PSW.Lineage.hq (AVIRA)
  • Infostealer (NAV)
  • Trojan.Killproc!gen (NAV)
  • W32/Lineage.NH (Norman)
  • W32/Lineage.RF (Norman)
  • PWS-Lineage.dll (NAI)
  • CHM_DROPPER.CLM (PCCIL)
  • TSPY_LINEAGE.AJ (PCCIL)
  • Trojan.PSW.Lineage.GEN (Rising)
  • Trojan-GameThief.Win32.Nilage.ha [AVP] (FSecure)
  • CHM_DROPPER.CLM (TrendMicro)
  • TSPY_LINEAGE.AJ (TrendMicro)