Virus: TR/PSW.Magania.azha Date discovered: 21/04/2009 Type: Trojan In the wild: Yes Reported Infections: Low Distribution Potential: Low Damage Potential: Low Static file: Yes File size: 108.855 Bytes MD5 checksum: 98221cfe63bb832de9ce9a3ad44384ff IVDF version: 7.01.03.80 - Tue, 21 Apr 2009 09:10 (GMT+1)
General Method of propagation: • No own spreading routine Aliases: • Symantec: Trojan.Packed.NsAnti • Kaspersky: Trojan-GameThief.Win32.Magania.azha • F-Secure: Trojan-GameThief.Win32.Magania.azha • Panda: W32/Lineage.KSZ • Eset: Win32/PSW.OnLineGames.NMY • Bitdefender: Trojan.PWS.OnlineGames.KBXH Platforms / OS: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads a file • Drops a file • Drops malicious files • Registry modification • Steals information Files It copies itself to the following locations: • %SYSDIR% \olhrwef.exe • C:\ej10fkdo.bat It deletes the initially executed copy of itself. The following files are created: – C:\autorun.inf This is a non malicious text file with the following content: • %code that runs malware% – %SYSDIR% \drivers\klif.sys Further investigation pointed out that this file is malware, too. Detected as: RKit/OnlineGames.CG.1 – %SYSDIR% \nmdfgds0.dll Further investigation pointed out that this file is malware, too. Detected as: TR/PSW.Wow.ife Registry The following registry keys are added in order to load the service after reboot: – [HKLM\SYSTEM\ControlSet001\Services\KAVsys] • Type=dword:00000001 • ErrorControl=dword:00000001 • Start=dword:00000001 • ImagePath="\??\%SYSDIR% \drivers\klif.sys" Injection – It injects itself into a process. Process name: • explorer.exe File details Programming language: The malware program was written in MS Visual C++. Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.See a brief description here . Description inserted by Andreas Feuerstein on Wed, 06 May 2009 15:28 (GMT+1) Description updated by Andreas Feuerstein on Wed, 06 May 2009 16:02 (GMT+1)