About     ru | pl
 
AV-School.com
AV-School - New source of IT-knowledge!
All-in-row News Articles
Articles » Security
Security Online games and fraud. Battle Trojan complex
The number of online games is constantly growing and the amount of money of this market is growing too. It provokes criminals to improve the malicious software which is used to steal player's personal data. In this article Trojan family of Trojan-GameThief.Win32.OnLineGames will be explored. Thousands modifications of this family appear every day.


Figure 1. Detection statistics of Trojan-GameThief.Win32.OnLineGames: 2008.12.01 - 2009.08.23





Figure 2. Age groups online – players





Figure 3. Percentage of time spent on online-games a week







Figure 4. Scheme of cheating in online-games








    



    








Figure 5. Trojan complex Trojan-GameThief.Win32.OnLineGames.bkzf





Figure 6. Strings of modified file userinit.exe





Figure 7. Comparison of MD5 hashes of the original and modified file userinit.exe





Figure 8. List of terminated processes









Figure 9. Command line for the completion of service and process.



    

    
    



Figure 10. The injection of malicious code in the address space of the process svchost.exe





Figure 11. Definition of malicious flow in the process svchost.exe





Figure 12. Disassembling of the malicious thread





Figure 13. The display of service in the Registry Editor





Figure 14. Replacing of handler NtQuerySystemInformation







Figure 15. Sale of accounts to the game Eve Online (http://accountgear.com/buy/Eve-Online)





Figure 16. Google trends





Alexander Saprykin, Alexander Nepokupny
"Design and Test Lab", Ltd. 2009

/specially for /



Article from blog: Marina.
TEXT +   TEXT -   Print Published : 24 December 2009 | Views : 379

Comments:
No comments. Go back.

To add comment

you have to register!
Total number of registered users:  317 
Online:  3 
Newbe: MayonnaTonfub

Who's online:
Guests online:  3 
Maximum online (26 Jan 2010)  21 
Blogs: 13
Posts: 68
Last: 01 Sep 2010
Comments: 78
Last: 23 Aug 2010
 Add new post
 All blogs
   Site Map    Feedback    About
Copyright © 2007-2010 «Kaspersky Lab.» : Powered By Danneo RCMSRSS