Softpedia
 

WINDOWS CATEGORIES:



GLOBAL PAGES >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>

WEEK'S BEST

  • DAEMON Tools Pro (...
  • FlashFXP [ DISCOUN...
  • PowerISO 4.9
  • WebcamMax [DISCOUN...
  • Zemana AntiLogger ...
  • System Mechanic Pr...
  • Glary Utilities Pr...
  • All My Movies [DIS...
  • Ad-Aware Internet ...
  • Atlantis Word Proc...
  • Home > Windows > Antivirus > Removal Tools
     Report malware

    Trojan.PWS.OnlineGames.KBVT Remover

    download button

    Downloads: 535  Tell us about an update
    User Rating:
    Rated by:
    NOT RATED
    0 user(s)
    Developer:

    License / Price:

    Size / OS:

    Last Updated:

    Category:

    Freeware / $0
    384 KB / Windows All

    C: \ Antivirus \ Removal Tools

     Read user reviews (0)  Send to friend   Follow (0 users)

    Trojan.PWS.OnlineGames.KBVT Remover description

    Clean the Trojan.PWS.OnlineGames.KBVT malware infection from your computer

    Trojan.PWS.OnlineGames.KBVT Remover is a simple command-line tool designed to help you get rid of the virus infection in no time.

    This is another onlinegames password stealer. When first run the malware will perform the following actions:

    - make a hidden copy of itself in %System% folder under olhrwef.exe and create the following registry key
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    Name: cdoosoft
    Value: "%System%\olhrwef.exe
    in order for this copy to be run at every system startup

    - drop a hidden .dll file named nmdfgds0.dll or nmdfgds1.dll in %System% folder - this is the component responsible for password stealing. It will be injected in all running processes and will monitor mouse gestures and keystrokes. some of the targeted online games are: MapleStory, Age Of Conan, Rohan, The Lord OF The Rings, Knight Online, Lands Of Aden and others.

    - create a hidden autorun.inf file on each drive which points to a hidden copy of the malware found in %drive_letter%\1ogf.exe used to spread itself via removable drives

    - drop a driver file named klif.sys in %dirvers% folder and create the following registry key in order for this driver to be loaded as a service at every system startup
    HKEY_LOCAL_MACHINE\Software\CurrentControlSet\Services\KAVSys
    Type: 0x1
    ErrorControl: 0x1
    Start: 0x1
    ImagePath: %drivers%\klif.sys
    This driver file, along with another .dll file named ANTIVM.dll, will be used to disable the update for different antivirus software or to stop processes that may be used to monitor running programs behaviour (in order to make analysis more difficult).

    - it will also add the following modifications to registry settings
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\
    CheckedValue = 0x00000000
    so that the user won't be able to see hidden files and folders in explorer while browsing the file system.

    - it will download the following file http://[removed]uw2..com/xmfx/help1.rar and save it in %temp% folder (when this description was made the file wasn't available anymore)

     Softpedia guarantees that Trojan.PWS.OnlineGames.KBVT Remover is 100% CLEAN, which means it does not contain any form of malware, including spyware, viruses, trojans and backdoors. [read more >]


    TAGS:

    OnlineGames virus | OnlineGames remover | trojan remover | OnlineGames | trojan | antivirus



    HTML code for linking to this page:


    Go to top

    WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

    SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM