English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Trojan-GameThief.Win32.OnLineGames.sint

Detected Jan 11 2001 07:55 GMT
Released Jul 21 2008 22:01 GMT
Published Jan 11 2001 07:55 GMT

Technical Details

This is email worm spreading by affecting MS Outlook. The worm itself is Win32 executable file about 30K of length. The worm is written in Visual Basic language.

When the worm is run it copies itself to Windows directories with the names:

C:\Windows\Vicevi_teza_odvala.txt.exe
C:\windows\system\Vicevi_teza_odvala.txt.exe

The second file is then registered in system registry auto-run key:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Sintesys = c:\windows\system\Vicevi_teza_odvala.txt.exe

The "C:\Windows" directory name is hardcoded in worm code, so it is not able to affect the system in case Windows directory name is not like that one.

The worm also copies itself with the same name to root directories of all available logical drives (local or remote).

The worm then connects to MS Outlook by using MAPI functions, gets all addresses from Address Book and sends messages to all of them. The messages have:

Subject: Vicevi!
Attach: Vicevi_teza_odvala.txt.exe

Text body is randomly selected from four variants:

Cao! Izvini sto te uznemiravam ovako, ali evo saljem ti neke viceve koji cete sigurno oraspoloziti!

Vozdra! Evo pogledaj ove viceve koje sam i ja dobio neki dan! Pravo su smijesni!

Cao korisnice! Znam da sigurno nemas vremena da pogledas ove viceve koje ti saljem. Nadam se da ces imati vremena da ih pogledas!

Zdravo! Nemoram ti nista pricati...samo pogledaj ovu veliku kolekciju viceva ;)

Vicevi!- Message
  Cao! Izvini sto te uznemiravam ovako, ali evo saljem ti
  neke viceve koji cete sigurno oraspoloziti!

To hide its activity the worm displays the fake error messages:

...cash!
  Raspakuj viceve!

WinZip SelfExtractor: Warning
  CRC error: 234#21


Bookmark and Share
Share
Trojan-GameThief

This type of malicious program is designed to steal user account information for online games. The data is then transmitted to the malicious user controlling the Trojan. Email, FTP, the web (including data in a request), or other methods may be used to transit the stolen data.


Other versions

Aliases

Trojan-GameThief.Win32.OnLineGames.sint (Kaspersky Lab) is also known as:

  • Trojan: PWS-Gamania.gen.a (McAfee)
  • Mal/LineDLL-B (Sophos)
  • W32/Gamania.gen (Panda)
  • W32/OnlineGames.gen (FPROT)
  • PWS:Win32/OnLineGames.DL!dll (MS(OneCare))
  • Trojan.Nsanti.Packed (DrWeb)
  • Win32/Pacex.Gen virus (Nod32)
  • Packer.Malware.NSAnti.1 (BitDef7)
  • Win32:OnLineGames-EVY [Trj] (AVAST)
  • Trojan-GameThief.Win32.OnLineGames.sint (Ikarus)
  • Packer.Malware.NSAnti.1 (Ikarus)
  • PSW.OnlineGames (AVG)
  • Trojan.Packed.NsAnti (NAV)
  • PWS-Gamania.gen.a (NAI)
  • Mal_Infostl (PCCIL)
  • Trojan.PSW.Win32.GameOL.oue (Rising)
  • Mal_Infostl (TrendMicro)