Trojan will make a copy of itself in %temp% as uret463.exe. Then it inject it into every running process starting with explorer explorer explorer.exe. The Trojan will steal login data from games like: TwelveSky, MapleStory, World of Warcraft. The DLL will drop lhgiyi[x]dll in the same folder (where [x] is any number) and inject it in the running process. It will send messages to all the harvested email addresses with the subject: You have got an e-card from your friend! and a version of itself attached.”]

