Malware

PWS:Win32/OnLineGames.IV information

Malware Removal

The PWS:Win32/OnLineGames.IV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/OnLineGames.IV virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine PWS:Win32/OnLineGames.IV?


File Info:

crc32: 22AF833E
md5: a0bc28e8f0b38bdb1ca235a8e88116b2
name: A0BC28E8F0B38BDB1CA235A8E88116B2.mlw
sha1: f2984acf6799f374e3dbc519cb15379d9cc0cecc
sha256: 26df17a5650af86da2685ed6c10592fcb200ccb6974f27320ac1a9b407411549
sha512: 4090fcd1e3a3db445c8b4d031b2b4380a0119abcf0c11f7fe0a6f224d555650b24ab36f6ae7df7abac59ef7e735224e24e4b1fb2a3791c46f4489c64d850758a
ssdeep: 6144:CxWiTMT5BI1a69t4wzu4OvEJXI40ec8treBZExW+UXa7STTZX8:uWicBNMt4wz31SkKBZtXQ8X8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PWS:Win32/OnLineGames.IV also known as:

BkavW32.AIDetectVM.malware
LionicTrojan.Win32.Agent.4!c
DrWebTrojan.KillProc.2113
MicroWorld-eScanTrojan.GenericKD.3116668
CMCTrojan.Win32.Agent!O
ALYacTrojan.GenericKD.3116668
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1289486
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/OnLineGames.1257b9ba
K7GWTrojan ( 005246d51 )
K7AntiVirusTrojan ( 005246d51 )
TrendMicroTROJ_ONLINEG.KYH
CyrenW32/OnlineGames.HG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.RRC
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Zusy-6840460-0
GDataTrojan.GenericKD.3116668
KasperskyTrojan.Win32.Agent.fntv
BitDefenderTrojan.GenericKD.3116668
NANO-AntivirusTrojan.Win32.Agent.ddfvqg
ViRobotTrojan.Win32.Agent.606208.G
TencentWin32.Trojan.Agent.Llqy
Ad-AwareTrojan.GenericKD.3116668
SophosMal/Generic-S
ComodoWorm.Win32.Dropper.RA@1qraug
F-SecureTrojan:W32/DelfInject.R
BitDefenderThetaGen:NN.ZexaF.34090.LqW@aCDRPHbb
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
FireEyeGeneric.mg.a0bc28e8f0b38bdb
EmsisoftTrojan.GenericKD.3116668 (B)
SentinelOneDFI – Malicious PE
F-ProtW32/OnlineGames.HG.gen!Eldorado
Endgamemalicious (high confidence)
WebrootW32.InfoStealer.OnlineGames.Gen
AviraTR/Agent.AQSE
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.Agent
MicrosoftPWS:Win32/OnLineGames.IV
JiangminTrojan/Agent.fvpw
ArcabitTrojan.Generic.D2F8E7C
ZoneAlarmTrojan.Win32.Agent.fntv
TACHYONTrojan/W32.Agent.606208.EK
AhnLab-V3Trojan/Win32.Agent.C130310
Acronissuspicious
McAfeeGenericRXBA-LF!A0BC28E8F0B3
MAXmalware (ai score=100)
PandaGeneric Malware
TrendMicro-HouseCallTROJ_ONLINEG.KYH
RisingTrojan.PSW.Win32.Ecode.p (CLOUD)
YandexTrojan.Agent2!mDcPdEJlIYo
IkarusTrojan.Win32.Agent
FortinetW32/Agent.FNTV!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.2ff

How to remove PWS:Win32/OnLineGames.IV?

PWS:Win32/OnLineGames.IV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment