TROJ_ONLINEG.LZG

 Analysis by: Christopher Daniel So

 PLATFORM:

Windows 2000, XP, Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted: Yes

  • In the wild: Yes


  TECHNICAL DETAILS

File Size:

10,752 bytes

File Type:

DLL

Memory Resident:

No

Initial Samples Received Date:

03 Sep 2010

Installation

This Trojan drops the following copies of itself into the affected system:

  • %User Temp%\lzg.tmp

(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)

Other Details

This Trojan does the following:

  • Copies %System%\dinput8.dll to %Current Folder%\dinput8_.dll
  • Terminates the following processes:
    • safeboxtray.exe
    • DragonNest.exe