These cracked games will infect your PC with malware that's damn hard to remove

A PC gamer using an RGB gaming keyboard and a Logitech gaming headset.
(Image credit: Shift Drive/Shutterstock)

If you download and install pirated PC games, your antivirus software could be turned off, Windows security updates could cease and your beloved GPU could be hijacked to mine cryptocurrency.

So warns a new report from antivirus firm Avast, which says that a new piece of coin-mining malware called "Crackonosh" has infected more than 200,000 Windows PCs since 2018, netting the crooks behind it about $2 million in Monero cryptocurrency.

"Crackonosh is distributed along with illegal, cracked copies of popular software and searches for and disables many popular antivirus programs as part of its anti-detection and anti-forensics tactics," wrote Avast researcher Daniel Benes. 

Infected downloads containing Crackonosh include "cracked" installers of Fallout 4 Game of the Year edition, Far Cry 5, Grand Theft Auto V, NBA 2K19, Pro Evolution Soccer 2018 and, um, The Sims 4 and The Sims 4 Seasons. 

If anecdotal reports cited by Avast were any indication, the cracked games played just fine, only with an extra bit of unseen menace.

Once a cracked game is installed, the malware makes some Windows Registry changes and installs a few executables that have names that sound like regular Windows services: winrmsrv.exe, winscomrssrv.dll and winlogui.exe. (The latter is the coin-mining part.) It lies in wait for a time, and then on the seventh or 10th restart after installation, boots the PC into Safe Mode.

Many cryptocurrency miners, aka "crypto-jackers," don't really do much damage to the machines they infect. They just want to "borrow" CPU and GPU cycles to generate coins. But Crackonosh is different.

An extra helping of malice

Because antivirus software doesn't operate in Safe Mode — even Windows' own Microsoft Defender Antivirus, aka Windows Defender — booting the PC into Safe Mode gives Crackonosh an opportunity to strike. 

It disables Microsoft/Defender, and deletes Avast, Bitdefender, F-Secure, Kaspersky, McAfee, Norton or Panda antivirus software if it's present. It then tweaks the Registry further to disable Windows security updates.

After all that, the malware will be ready to deploy the XMRig miner to hijack your cycles and generate Monero — and your computer will be  exposed to the full force of internet malware like a naked child in a cold winter.

If your machine suddenly has a lot of malware, your antivirus software is nowhere to be found and you haven't received a Windows update in months, you might be harboring Crackonosh. Getting rid of it isn't easy — Avast has a full set of how-to instructions in its report, but they're pretty technical and best left to someone who knows the intricacies of the Windows Registry.

It's best just to avoid infection altogether by not installing cracked software. If you feel you absolutely must, then scan each software installer with antivirus software before you run it. You can often just right-click the installer in your Downloads folder and then select "Scan with" the antivirus software of your choice from the pop-out menu.

"As long as people continue to download cracked software, attacks like these will continue to be profitable for attackers," wrote Avast's Benes. "The key take-away from this is that you really can't get something for nothing and when you try to steal software — odds are someone is trying to steal from you."

TOPICS
Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Read more
A magnifying glass on top of the Steam logo in a web browser
Valve recommends a full PC reset after malware-infected game discovered on Steam
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A hacker typing quickly on a keyboard
New MassJacker malware is hijacking digital wallets to steal large sums from users
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
One phone with skull and crossbones on screen among several other clean-looking phones.
Malicious iPhone apps are spreading screenshot-reading malware on the Apple App Store — how to stay safe
A hacker typing quickly on a keyboard
Hackers are posing as Apple and Google to infect Macs with malware — don’t fall for these fake browser updates
Latest in Malware & Adware
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Malware
Dangerous new password-stealing trojan automatically reinstalls itself on infected PCs
An FBI agent typing on a computer
FBI issues warning to millions of Americans to avoid these websites that can steal your passwords and banking info
A hacker typing quickly on a keyboard
New MassJacker malware is hijacking digital wallets to steal large sums from users
A person trying to set up a new Wi-Fi router
Thousands of TP-Link routers have been infected by a botnet to spread malware
A smartphone screen displaying the Android name and logo next to a sign reading 'MALWARE'.
Fake Google Play Store pages are spreading Trojan malware that can steal your financial data
Latest in News
Apple Watch Series 10
Future Apple Watch models could get a surprising new feature — what we know
NYTimes Connections
NYT Connections today hints and answers — Monday, March 24 (#652)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #386 (Monday, March 24 2025)
iPhone 16 Pro vs iPhone 16 Pro Max in hand showing displays
Forget iPhone 17 — iPhone 18 could get this huge upgrade
The new Husqvarna iQ series robot lawn mower.
Husqvarna’s new robot mowers offer GPS for less
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
  • COLGeek
    These are often the consequences of stealing content. Never use pirated/cracked content! You are only asking for trouble!
    Reply