June 21, 2008 one virus needs your attention. It is OBB (Trojan.PSW.Win32.GameOL.obb). This is a virus which steals game player password information. It will drop itself into Explorer.Exe process, then search game process, send game password information to hackers appointed website after recorded,
Name: OBB (Trojan.PSW.Win32.GameOL.obb)
Warning level: Dangerous
Category: Trojan
Affected System: Windows NT/2000/XP/2003
This is a Trojan which is stealing user game password. Virus will release file ayTQQTQQ1011.exe and ayTQQTQQ1011.dll to system32, and edit the registry start up to run itself when system start. This virus will drop dynamic basement into Explorer.exe process, if there is a game process, virus will drop itself into it, record game account number and password. Then, virus will send this information to an appointed website. Virus will be deleted by own after finish, to escape from anti-virus software’s scan.
Anti-virus experts suggest that computer users take the following measures to protect against this virus:
1. Install Rising Anti-virus, personal firewall, update in time, and at least 3 times per day for updating Rising.
2. Use Rising Vulnerability Check, patch your computer system in a timely manner as many viruses spread by taking advantage of the system exploits or vulnerabilities.
3. Do not browse suspicious websites, and suspicious inserter; turn off or delete unnecessary system services.
4. Do not receive the suspicious file from QQ, MSN, Email, etc.
5. Open auto-protect and auto-monitor function when accessing to the internet.
6. Put your account information of networks bank, networks game, MSN, QQ, Yahoo Messenger etc, into Rising Application Protection, Rising Application Protection can protect specified applications from attack by malicious programs. A user can apply rules to game software, instant messenger, etc. to customize protection.
*You can buy RISING Antivirus here or free download to try.
*If you have any questions about RISING products, please visit Rising support centre for help.