Select Page

Gamler Trojan travels to online games

The Gamler Trojan is primarily aimed at the computers of users who like online games.

A Gamler Trojan is simple in structure and operation. It creates only one file in the Windows System32 directory and uses a single entry added to the registry to ensure that it loads automatically each time Windows is restarted.

The main goal of the Trojan is to collect as much login information as possible from infected computers that can be used to connect to online games such as World of Warcraft and Lineage II. If you manage to obtain such confidential information, you will upload it to pre-defined websites compiled by the malware's creators.

Gamler Trojan travels to online games

When the Gamler Trojan starts, it performs the following actions:

  1. Create the following file:
    % System32% \ Ir32_a.exe
  2. Add the following entry to the registration database:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon”Userinit” = “C:\WINDOWS\system32\userinit.exe,Ir32_a.exe”
  3. It attempts to obtain login information (usernames and passwords) for online games
  4. It uploads the collected data to two pre-defined websites

About the Author