Spy

Should I remove “OnlineGames.Spyware.Stealer.DDS”?

Malware Removal

The OnlineGames.Spyware.Stealer.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What OnlineGames.Spyware.Stealer.DDS virus can do?

  • Attempts to make use of the Filter Manager
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine OnlineGames.Spyware.Stealer.DDS?


File Info:

name: AFCEF667601740C9F92E.mlw
path: /opt/CAPEv2/storage/binaries/9a77b8a82079bf64d625f303f1341fe85250684b8a8cb321e547f741c3f84d9a
crc32: EF5FF59E
md5: afcef667601740c9f92ef98b85ea00e9
sha1: a8db4bcfcceef0d63dffd7ee995bccc2acfe23ef
sha256: 9a77b8a82079bf64d625f303f1341fe85250684b8a8cb321e547f741c3f84d9a
sha512: 2cbe8711bb44c6f0dad99757c7e7642e46e638a244ac694c3e1538ba899e61390138836f248fb188fc56dbf64eb42655214290ef4b258d811b63a14400cf795b
ssdeep: 384:kVrPI9HH960YmiGlDThXvRLpDtpxkku8gQ0F:kV7MHH960YmiGxT5hpDuZ
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1A892DF3677FCCA6DE5DB9A320683A75521382CA0CF7B574B0AE583062E1625C7D70B29
sha3_384: 49a4c3c4b1ff4487923cb631d5cc551a21de98925f786a3247de930a0e7768472f1ed6687ad6cf8c2cbd783866e174f2
ep_bytes: 807c2408010f85b901000060be006001
timestamp: 2013-06-28 07:07:39

Version Info:

Comments:
CompanyName: vrv
FileDescription: Mndll
FileVersion: 1, 0, 0, 1
InternalName: Mndll
LegalCopyright: Copyright ? 2013
LegalTrademarks:
OriginalFilename: Mndll.dll
PrivateBuild:
ProductName: vrv Mndll
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x0804 0x04b0

OnlineGames.Spyware.Stealer.DDS also known as:

LionicTrojan.Win32.OnLineGames.d!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGeneric.Malware.SPf!dld!Pk!1g.D3D4B06A
ClamAVWin.Trojan.Onlinegames-17057
FireEyeGeneric.mg.afcef667601740c9
SkyhighBehavesLike.Win32.Dropper.mc
McAfeeGenericRXAA-FA!AFCEF6676017
MalwarebytesOnlineGames.Spyware.Stealer.DDS
VIPREGeneric.Malware.SPf!dld!Pk!1g.D3D4B06A
SangforTrojan.Win32.Save.a
K7AntiVirusPassword-Stealer ( 005148c31 )
AlibabaTrojanPSW:Win32/OnLineGames.d2dec463
K7GWPassword-Stealer ( 005148c31 )
CrowdStrikewin/malicious_confidence_90% (D)
ArcabitGeneric.Malware.SPf!dld!Pk!1g.D3D4B06A
BitDefenderThetaGen:NN.ZedlaF.36744.bmSfaGJkErkb
VirITTrojan.Win32.OnlineGames4.APPR
SymantecInfostealer.Gampass
ESET-NOD32a variant of Win32/PSW.OnLineGames.QPK
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-GameThief.Win32.OnLineGames.ajrfs
BitDefenderGeneric.Malware.SPf!dld!Pk!1g.D3D4B06A
NANO-AntivirusTrojan.Win32.OnLineGames.chwuns
SUPERAntiSpywareTrojan.Agent/Gen-PWS
AvastWin32:Trojan-gen
RisingStealer.OnLineGames!1.6610 (CLOUD)
EmsisoftGeneric.Malware.SPf!dld!Pk!1g.D3D4B06A (B)
BaiduWin32.Trojan-PSW.OLGames.as
F-SecureTrojan.TR/Spy.Gen
DrWebTrojan.PWS.Gamania.41553
ZillyaTrojan.OnLineGamesGen.Win32.1
TrendMicroTROJ_ONLINEGAMES_EK09029F.UVPM
SophosMal/Generic-S
IkarusTrojan-PSW.OnlineGames
JiangminTrojan/Generic.axorv
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Spy.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Unknown
XcitiumTrojWare.Win32.GameThief.OnLineGames.AJU@51o4ju
MicrosoftTrojan:Win32/Ditertag.A
ViRobotTrojan.Win32.PSWIGames.20992.AX
ZoneAlarmTrojan-GameThief.Win32.OnLineGames.ajrfs
GDataWin32.Trojan.PSE.17CUJBQ
VaristW32/OnlineGames.JV.gen!Eldorado
AhnLab-V3Win-Trojan/Patched3.Gen
ALYacGeneric.Malware.SPf!dld!Pk!1g.D3D4B06A
TACHYONTrojan/W32.KRBanker.73728.D
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_ONLINEGAMES_EK09029F.UVPM
TencentTrojan.Win32.OnlineGame.o
YandexTrojan.GenAsa!o9HMfwI3584
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.2F76!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove OnlineGames.Spyware.Stealer.DDS?

OnlineGames.Spyware.Stealer.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment