TSPY_ONLINEG.SMG
Windows 2000, Windows XP, Windows Server 2003

Threat Type: Spyware
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This spyware arrives as a component bundled with malware/grayware packages. It may be unknowingly downloaded by a user while visiting malicious websites.
It may be injected into processes running in memory.
It also has rootkit capabilities, which enables it to hide its processes and files from the user.
TECHNICAL DETAILS
Varies
EXE
Yes
21 Jan 2012
Arrival Details
This spyware arrives as a component bundled with malware/grayware packages.
It may be unknowingly downloaded by a user while visiting malicious websites.
Installation
This spyware may be injected into processes running in memory.
Rootkit Capabilities
This spyware also has rootkit capabilities, which enables it to hide its processes and files from the user.
NOTES:
It creates a backup of the WS2HELP.dll as %System%\wimedump.dll.
It then deletes the file WS2HELP.dll.
This file may be used by its main component to steal information related to online games.