Malware

What is “MSIL/PSW.OnLineGames.EV”?

Malware Removal

The MSIL/PSW.OnLineGames.EV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/PSW.OnLineGames.EV virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine MSIL/PSW.OnLineGames.EV?


File Info:

name: A4D5EBD13B689F6121ED.mlw
path: /opt/CAPEv2/storage/binaries/53f00b6837a8bd2b927504d4102ea91da80b7be1d7e737c431020119d65bf251
crc32: 1B34E7D1
md5: a4d5ebd13b689f6121ed97164489b9d3
sha1: 10864722486dcd94afeade28caa1de418a79b085
sha256: 53f00b6837a8bd2b927504d4102ea91da80b7be1d7e737c431020119d65bf251
sha512: 837f7b7d9962cf9f6adac7b39f20497186c95835cf290707bbbf77741972d4a8d21a643e303ce4dd78503d050a9d4d8380a1d79cd0040faed50971148c4302b6
ssdeep: 6144:Q0GviJgzUDinEk125HsZeXP0hSY6Y2zR:uvioUDi125HoqrN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FF2412252BC9DF74DCBF6F308AA055121FF2AC22EA43EB7EAD4471555A331028EC1B95
sha3_384: a5307024bd32e3a335e28ea8e1829a9574ebcb1f45a7fbda4f7b22e4fabadffca5af1e69178b86939ac69f42c0f814d7
ep_bytes: ff250020400000000000000000000000
timestamp: 2010-06-18 20:33:22

Version Info:

Translation: 0x0000 0x04b0
CompanyName: HOME
FileDescription: chips hack
FileVersion: 1.0.0.0
InternalName: chips hack.exe
LegalCopyright: Copyright © HOME 2010
OriginalFilename: chips hack.exe
ProductName: chips hack
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/PSW.OnLineGames.EV also known as:

FireEyeGeneric.mg.a4d5ebd13b689f61
VIPRETrojan.Win32.Generic!BT
K7AntiVirusPassword-Stealer ( 005538f41 )
K7GWPassword-Stealer ( 005538f41 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZemsilCO.34084.nq0@aCPg@!d
CyrenW32/MSIL_Troj.BLQ.gen!Eldorado
ESET-NOD32MSIL/PSW.OnLineGames.EV
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:MSIL/Crime.c2d00216
NANO-AntivirusTrojan.Win32.RiskGen.ecpzex
McAfee-GW-EditionBehavesLike.Win32.Trojan.dc
SentinelOneStatic AI – Malicious PE
APEXMalicious
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1106944
Antiy-AVLTrojan/Win32.Tgenic
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
McAfeeArtemis!A4D5EBD13B68
MalwarebytesGeneric.Malware/Suspicious
YandexTrojan.PWS.OnLineGames!epL8LFoDNMk
IkarusTrojan-Spy.MSIL.Crime
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.NQK!tr
WebrootW32.Trojan.Gen
AVGWin32:Malware-gen
Cybereasonmalicious.2486dc
AvastWin32:Malware-gen

How to remove MSIL/PSW.OnLineGames.EV?

MSIL/PSW.OnLineGames.EV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment