Check Raised RBCalc.exe Online Poker Calculator has Money-Stealing Small.la Trojan On Board   - 2,852 Views,

Summary: Check Raised's RBCalc.exe has the Backdoor.Win32.Small.la (Small.la for short) rootkit trojan hiding in it. It contains the following trojan files: utlsrv.exe, comclg32.dll, d3dclsrv.dll and ndsdavsrv.sys.

Previous Article « Take Back the Net - Secure Your Computer!
Read Next Article » Security Hole in Word Allows Attack Through Email with Ginwui.a Trojan

  Follow Anne on Twitter

Check Raised’s RBCalc.exe Online Poker earnings calculator has the Backdoor.Win32.Small.la (Small.la for short) rootkit trojan hiding in it according both to online security company F-Secure, and Check Raised itself.

F-Secure explains that “Small.la is a spying trojan that targets several online poker games. It was distributed from a website checkraised.com using a trojaned Rakeback calculator application (RBCalc.exe). The trojan hides itself using rootkit techniques.” Once running, it monitors your accounts at several online poker sites, allowing the programmer behind the trojan to steal your poker account money - often by simply making it look like you played some losing hands, so you’ll never suspect something is amiss if you don’t pay really close attention to your accounts.

According to Check Raised, the trojan was slipped into its RBCalc.exe program by a programmer who worked on the program, which Check Raised began offering nearly sixth months ago, in December of 2006. Check Raised said that because the trojan was undetectable by many popular anti-virus programs, they had no idea about it until a third party brought it to their attention recently.

Check Raised goes on to say that “If you have ever used rbcalc please read the following to check if the malicious software is on your machine and how to remove it. This virus could also come bundled with other poker applications, so please read the following even if you have never heard of rbcalc.”

When you run RBCalc.exe, Backdoor.Win32.Small.la silently copies four files into your Windows system directory. These files are:

utlsrv.exe
comclg32.dll
d3dclsrv.dll
ndsdavsrv.sys

It then runs utlsrv.exe and begins spying all all of these applications:

PartyGaming.exe
mppoker.exe
poker.exe
gameclient.exe
ultimatebet.exe
absolutepoker.exe
mainclient.exe
pokerstars.exe
pokerstarsupdate.exe
partypoker.exe
fulltiltpoker.exe
pokernow.exe
multipoker.exe
empirepoker.exe
eurobetpoker.exe

Check Raised has instructions for finding and removing Small.la here.

Check Raised RBCalc.exe Online Poker Calculator has Money-Stealing Small.la Trojan On Board

 Follow Anne on Twitter

 Twitter Explained in Plain English

 Friend Anne on Facebook

Previous Article « Take Back the Net - Secure Your Computer!
Read Next Article » Security Hole in Word Allows Attack Through Email with Ginwui.a Trojan

Read more:

»  Yahoo Raises Price of Music Downloads on Yahoo Music Unlimited

»  Find Out Who Obama’s VP Running Mate Will Be by Text Message

»  Looking for Recording Contracts to Get an Album Recorded? Check Out SellaBand!

»  Gmail Ad Nauseum I: EFF Issues Gmail Alert

For additional similar stories check out our archives on Gaming, Security

NOTE: We never, ever, ever will recommend any product or service on this site that we have not regularly used ourselves and do not wholeheartedly believe in. That said, in some cases after being very pleased with a product or service, we may enter into a relationship with the provider of that product or service such that if someone purchases that product or service based on our recommendation, we may get a small payment. Such payments go towards the upkeep of the Internet Patrol.

 

No Comments »

No comments yet.

RSS feed for comments on this post.

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


If you have not posted a comment here before, we apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day! You only need to do this once; once you have successfuly posted a comment here you will not be asked to do this again. Thank you for your understanding!

 
 This article first appeared on 5/20/2006
The Internet Patrol
Patrolling the Internet for You!