Home Malware Programs Trojans PWS:Win32/OnLineGames.KQ

PWS:Win32/OnLineGames.KQ

Posted: January 7, 2013

Threat Metric

Threat Level: 8/10
Infected PCs: 49
First Seen: January 7, 2013
Last Seen: March 26, 2022
OS(es) Affected: Windows

PWS:Win32/OnLineGames.KQ is a Trojan that steals passwords for online games from affected web users. Once installed on the corrupted PC, PWS:Win32/OnLineGames.KQ makes system changes by dropping potentially malicious files. PWS:Win32/OnLineGames.KQ is installed as a DLL file, and when loaded by 'iexplore.exe', PWS:Win32/OnLineGames.KQ attempts to steal user account credentials if the computer user logs on to any of certain websites. PWS:Win32/OnLineGames.KQ also monitors and captures the PC user's credentials if certain processes linked to online games are running on your computer system. PWS:Win32/OnLineGames.KQ may log the collected information into certain files. PWS:Win32/OnLineGames.KQ then transmits the gathered data to any of certain websites via HTTP POST.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C__Users_god_AppData_Local_Temp_WinSocketA.dll File name: C__Users_god_AppData_Local_Temp_WinSocketA.dll
Size: 39.42 KB (39424 bytes)
MD5: 2edf4930eb8c9546ea85376d01093563
Detection count: 75
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: February 25, 2013
b3b1ff527c249b258374c47572400169 File name: b3b1ff527c249b258374c47572400169
Size: 77.82 KB (77824 bytes)
MD5: b3b1ff527c249b258374c47572400169
Detection count: 74
Group: Malware file
Last Updated: February 25, 2013
ws2help.dll File name: ws2help.dll
Size: 90.11 KB (90112 bytes)
MD5: aa183069409b28591612bb0da9d03fed
Detection count: 71
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: February 25, 2013
C:\Users\<username>\Desktop\NanoCore 1.2.2.0 Cracked By Alcatraz3222_Final\theZoo-master\malwares\Binaries\Variant.Kazy\21.exe File name: 21.exe
Size: 56.22 KB (56224 bytes)
MD5: ebefee9de7d429fe00593a1f6203cd6a
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop\NanoCore 1.2.2.0 Cracked By Alcatraz3222_Final\theZoo-master\malwares\Binaries\Variant.Kazy\21.exe
Group: Malware file
Last Updated: March 26, 2022
[system folder]\imm32b.dll File name: [system folder]\imm32b.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
[system folder]\win32.dll File name: [system folder]\win32.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
[system folder]\ws2help.dll File name: [system folder]\ws2help.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%APPDATA%\gdx.exe%HOMEDRIVE%\Cache\ModuleW.exe
Loading...