Analysis by: Erika Bianca Mendoza

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 REPORTED INFECTION:
 SYSTEM IMPACT RATING:
 INFORMATION EXPOSURE:

  • Threat Type: Spyware

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This spyware arrives as a component bundled with malware/grayware packages. It may be unknowingly downloaded by a user while visiting malicious websites.

It may be injected into processes running in memory.

It also has rootkit capabilities, which enables it to hide its processes and files from the user.

  TECHNICAL DETAILS

File Size: Varies
File Type: EXE
Memory Resident: Yes
Initial Samples Received Date: 21 Jan 2012

Arrival Details

This spyware arrives as a component bundled with malware/grayware packages.

It may be unknowingly downloaded by a user while visiting malicious websites.

Installation

This spyware may be injected into processes running in memory.

Rootkit Capabilities

This spyware also has rootkit capabilities, which enables it to hide its processes and files from the user.

NOTES:

It creates a backup of the WS2HELP.dll as %System%\wimedump.dll.

It then deletes the file WS2HELP.dll.

This file may be used by its main component to steal information related to online games.