Newly released ( LAST WEEK) SMG.heu!gen Trojan *EXECUTED* through League of legends client location.

Blim Jimmy·12/9/2018, 12:27:47 AM·2 votes·1,018 views

Was looking to submit a ticket but couldn't find a category to suite, so i'm starting here, please move / contact directly if possible.

First off, Riot Games has no involvement with this Trojan, the file only simply got executed within the League of Legends file location.

Now that has been disclosed, here's the issue that has since been resolved (under 5 minutes) due to a free version of Norton LOL. Okay so, this PC was freshly built within the last month, I DO NOT have anything on this Device To Compromise it, other than your general gaming apps,

Ex, league, battle.net, discord etc.

I'm not an IT but i have been recently keeping up to date with the DEF CON hacking conference for the past couple of years and have confidence Norton's Firewall was accurate in it's finding as i have checked files within league of legends before hand and have never seen these files before.

Earlier around 3:00 - 4:00 i had played only two games, the first being nexus blitz and the other match ARAM (The match ultimately in question), i finished the match and went out for half hour tops, when i got back Norton had found something (pictures and logs still grab-able for staff only).

What i will disclose here is that as stated above the file appeared at "X Time" and had executed "X minutes later" (due to the client being open) Luckily while i was AFK Norton had stopped this execution and quarantined both the root file and the whole whopping 1 file it managed to make, (Weak execution i know).

I Approached the situation with caution as this Trojan could get out of hand if i had clicked "Restore Files" and white listed the files, i located the files in question and peeked at several things to confirm Norton's findings. The files deemed threatening were being masked / executed were "00031626.tmp" and "00007904.tmp" and ultimately was a Newly released "SMG.heu!gen Trojan Virus" within the Client folder, (Norton had deemed it low risk) THIS IS NOT LOW RISK.

The Findings / Countermeasures taken lead me to believe my IP was grabbed within the stated time frame above playing league of legends. The issue has been resolved since in a respectable manner but i have not wiped anything as it was not needed and I am easily able to manage and confirm every windows 10 processes, background tasks and apps that may be running.

I am sharing this here in hopes of confirming this further / helping others and ultimately getting a patch out to protect others.

All Logs available for staff upon request.

0 Comments