Home Malware Programs Trojans Wowcraft.c

Wowcraft.c

Posted: March 28, 2006

Wowcraft.c is a trojan that monitors opened windows and steals user login names and passwords related to popular PC games "World of Warcraft" and "The Legend of Mir". Gathered data is transferred to a predefined remote host. Wowcraft.c can also terminate running security-related software and log user keystrokes. The trojan automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 debugprogram.exe
    2 dxdiag.com
    3 exert.exe
    4 intexplore.com
    5 intexplore.pif
    6 lsass.exe
    7 msconfig.com
    8 regedit.com

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}871C5380-42A0-1069-A2EA-08002B30309DshellOpenHomePageCommand(Default)=C:ProgramFilesInternetExplorerintexplore.com%1HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainCheck_Associations=noHKEY_LOCAL_MACHINESOFTWAREClasses.exe(Default)=%Windir%exert.exe"%1"%*HKEY_LOCAL_MACHINESOFTWAREClasses.exe(Default)=WindowFilesHKEY_LOCAL_MACHINESOFTWAREClassesHTTPShellOpenCommand(Default)=C:ProgramFilesCommonFilesintexplore.pif-nohomeHKEY_LOCAL_MACHINESOFTWAREClassesWindowFilesShellOpenCommand(Default)=%Windir%exert.exe"%1"%*HKEY_LOCAL_MACHINESOFTWAREClassesWindowFilesShellOpenCommand(Default)=WindowFilesHKEY_LOCAL_MACHINESOFTWAREClassesftpShellOpenCommand(Default)=C:ProgramFilesInternetExplorerintexplore.com%1HKEY_LOCAL_MACHINESOFTWAREClasseshtmlfileShellOpenCommand(Default)=C:ProgramFilesCommonFilesintexplore.pif%1HKEY_LOCAL_MACHINESOFTWAREClasseshtmlfileShellOpenCommand(Default)=C:ProgramFilesInternetExplorerintexplore.com-nohomeHKEY_LOCAL_MACHINESOFTWAREClientsStartMenuInternetintexplore.pifHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunop=%Windows%lsass.exe
Loading...