Trojan-GameThief.Win32.Magania.cjqd

Trojan-GameThief.Win32.Magania.cjqd
Threat Name: Trojan-GameThief.Win32.Magania.cjqd
Different descriptin:Net-Worm.SillyFDC [PCTools]
W32.SillyFDC [Symantec]
Trojan-GameThief.Win32.Magania.cjqd [Kaspersky Lab]
PWS-Mmorpg!ha [McAfee]
Mal/Taterf-B, Mal/Taterf-A [Sophos]
Worm:Win32/Taterf.B [Microsoft]
Dropper/OnlineGameHack.116183 [AhnLab]
Spread Method:
Windows Vulnerability
E-Mail
detect files name: C:\nds0q.exe
%Temp%\cvasds0.dll
%Temp%\cvasds1.dll
%Temp%\cvasds2.dll
%Temp%\herss.exe
c:\nds0q.exe
c:\autorun.inf
The newly created Registry Value is:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
cdoosoft = “%Temp%\herss.exe”
Threat type:Trojan-GameThief.Win32
Trojan-GameThief.Win32.Magania.cjqd first detected:2010-02-28
Virus file known is Unkown type
File Size:587K Bytes.
Behavior:Attempted Connection to External Sites
Level of Spread:2
Level of Threat:6
Reported Path:Unkonow path
MD5:i2ttoV6YuKowIsevPh0BV7r0D45X30M1
SHA1..:5Oc08wYh1lp2kb4eq5JjxE0HlTWgRInL8q3311hi