Home Malware Programs Trojans PWS-OnlineGames.kc

PWS-OnlineGames.kc

Posted: February 28, 2011

PWS-OnlineGames.kc is a particular noteworthy threat to gamers, as a Trojan with the ability to hone in on and steal game account-related information such as passwords and other login info. Since it's a Trojan, PWS-OnlineGames.kc may also drop other malware such as rogue programs, viruses or worms to cause further harm to the system. PWS-OnlineGames.kc registers a .dll and a Browser Help Object and may be a keylogger. As a massive invasion of your privacy and a non-negligible danger to your security, this Trojan should be thought of as a serious risk for any computer; deleting PWS-OnlineGames.kc forthwith should be your only reaction.

PWS-OnlineGames.kc's Distribution and Initial Behavior

Trojans like PWS-OnlineGames.kc tend to propagate by way of widely-distributed infected files and dangerous website code. Avoiding risky file sources from China will especially enhance your ability to sidestep PWS-OnlineGames.kc infections, since this Trojan most likely originates from that country. If your anti-virus programs have updated threat databases and are active all the time, PWS-OnlineGames.kc shouldn't be able to sneak in easily.

If you acquire a PWS-OnlineGames.kc infection, you're unlikely to notice PWS-OnlineGames.kc at first. PWS-OnlineGames.kc isn't likely to give too many plain visual signs of activity. Additions to your Windows registry will let PWS-OnlineGames.kc run in the background with nary a peep, although other malware downloaded by PWS-OnlineGames.kc may be more intrusive.

These registry changes may also have other undesired effects, since PWS-OnlineGames.kc has been indicated to deliberately corrupt already-present registry entries to some extent.

PWS-OnlineGames.kc is in Your Computer, Stealin' Your Passwords

Just as you might expect from the name, PWS-OnlineGames.kc's main goal is to grab all your game account passwords and other relevant login info. PWS-OnlineGames.kc is been noted to target less popular games such as Lineage, Rohan and Legmir as well as more mainstream ones such as World of Warcraft. A stolen game account is then generally used for botting, selling items and other illegal activities. Once you've noticed a compromised account, acting fast and contacting the relevant game company might allow you to get your account password reset and any recent changes reverted. All this will do you little good, however, if you don't also delete PWS-OnlineGames.kc to prevent further attacks.

Some trademark signs of PWS-OnlineGames.kc infection include:

  • Registration of a malicious .dll file.
  • Registration of a malicious BHO or Browser Help Object.
  • An unknown process connecting to a remote IRC server without the user's permission.

As if all that wasn't enough, PWS-OnlineGames.kc is also reported as a potential keylogger. Keylogging allows PWS-OnlineGames.kc to record each stroke typed on your keyboard even if that information isn't later saved to a file. Such high-level spying capabilities make deleting PWS-OnlineGames.kc an important task even if you don't possess online game accounts.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %PROGRAM_FILES%\PWS-OnlineGames.kc c:\Documents and Settings\All Users\PWS-OnlineGames.kc\ %PROGRAM_FILES%\PWS-OnlineGames.kc
    2 c:\Documents and Settings\All Users\Start Menu\PWS-OnlineGames.kc\
Loading...