Malware

How to remove “PWS:Win32/OnLineGames.GG”?

Malware Removal

The PWS:Win32/OnLineGames.GG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/OnLineGames.GG virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with NsPack
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine PWS:Win32/OnLineGames.GG?


File Info:

name: DDE7EB8D9480DB8BC51C.mlw
path: /opt/CAPEv2/storage/binaries/216ffc0d62d29c80c43101ae7c0a57234c7a9383c832d1905cb05901dca40fb4
crc32: 67515C29
md5: dde7eb8d9480db8bc51cf0853d0252c8
sha1: 0c1a98166822b98fe8f06408b230b4cafdb238a3
sha256: 216ffc0d62d29c80c43101ae7c0a57234c7a9383c832d1905cb05901dca40fb4
sha512: aa00bb4e7d437e7d5749e29afe6f45a48306d7bc22b38eb205b95c4d17450819fa54d53d35edd6959c00dac622a656b7903482ec875c6527622c2b5ac376597c
ssdeep: 6144:UE2zko74Z9ysG5dn456jGf/2C2YTJSnYLvZ8elAeCg9tq/wPaV:UE2jcgnc6je/2C23nYLvZ8K3GVV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B7E41293C618B645D0C44270DAFAAB047AB69C435A77D97E28B03EA5CBF16C21F350ED
sha3_384: 6599a47bb97333df2cf1536d3581911a0b388dc1dc4a65a45ecb355123e6487d8d38a28961a40c4398102a60660e94d0
ep_bytes: 83d079e8d85d0200b5830f3837e73fbe
timestamp: 2009-08-28 13:35:06

Version Info:

0: [No Data]

PWS:Win32/OnLineGames.GG also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Packed.551
MicroWorld-eScanGen:Trojan.Generic.OmW@aak5Fvbb
FireEyeGeneric.mg.dde7eb8d9480db8b
McAfeeArtemis!DDE7EB8D9480
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005257651 )
K7AntiVirusTrojan ( 005257651 )
BitDefenderThetaAI:Packer.543E6F681C
CyrenW32/Trojan-Gypikon-based.DM2!Ma
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/PSW.OnLineGames.OXO
APEXMalicious
TrendMicro-HouseCallMal_Banker
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Trojan.Generic.OmW@aak5Fvbb
NANO-AntivirusTrojan.Win32.ULPM.dfhfzy
AvastFileRepMalware [Trj]
TencentWin32.Trojan-PSW.2.Dtgl
Ad-AwareGen:Trojan.Generic.OmW@aak5Fvbb
EmsisoftGen:Trojan.Generic.OmW@aak5Fvbb (B)
ComodoPacked.Win32.MNSP.Gen@2697wr
VIPREGen:Trojan.Generic.OmW@aak5Fvbb
TrendMicroMal_Banker
McAfee-GW-EditionBehavesLike.Win32.Generic.jm
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/Behav-043
IkarusTrojan-Dropper.Win32.Delfsnif
JiangminBackdoor/Agent.cfti
GoogleDetected
AviraTR/Crypt.NSPM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.37EA
MicrosoftPWS:Win32/OnLineGames.GG
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Trojan.Generic.OmW@aak5Fvbb
CynetMalicious (score: 100)
VBA32BScope.Trojan-Spy.Zbot
ALYacGen:Trojan.Generic.OmW@aak5Fvbb
MAXmalware (ai score=82)
MalwarebytesMalware.Heuristic.1003
ZonerProbably Heur.ExeHeaderP
RisingPacker.Win32.Agent.bd (CLASSIC)
YandexTrojan.Hupigon.Gen!Pac.6
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.KYT!tr
AVGFileRepMalware [Trj]
Cybereasonmalicious.d9480d
PandaTrj/CI.A

How to remove PWS:Win32/OnLineGames.GG?

PWS:Win32/OnLineGames.GG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment