Malware

PWS:Win32/OnLineGames.JB removal guide

Malware Removal

The PWS:Win32/OnLineGames.JB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/OnLineGames.JB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine PWS:Win32/OnLineGames.JB?


File Info:

name: 8CF6232AF1978164B2DD.mlw
path: /opt/CAPEv2/storage/binaries/bb5e6f03d6eaf771f0833fcad8e053869b6a9ff55c263b4f4f9229f53b8b730e
crc32: E7E8DCCA
md5: 8cf6232af1978164b2dd2f49742e5c63
sha1: 53c9743e21a867def33b57dbad481a48c8667bd5
sha256: bb5e6f03d6eaf771f0833fcad8e053869b6a9ff55c263b4f4f9229f53b8b730e
sha512: 08470ae81db83024261c3f59d2dca2c58cc47ff8a9be8502736cbc6174c0069d0e27702ac33c71849c6b6b8b394c7f9aa468b3e7c18d57040f3c14ca0309964b
ssdeep: 1536:MxvNbz0ZBTYCsL0k2n2mzRrJ8pmvXBDS1Vi4R+D9OJ8oIl9BRn:OB0BTYCsDqBrb4R+BOeJP
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T12E93BFDD96212137D37F8A3785963E3F4A3A11B22E5B506BD33610E93877192AB05F0B
sha3_384: 65feea4d44d2ca75ce9e11ab70ad2f51897c7427b4d9f65d8b38473b5826807f21f50a8796adaab6ca831df95b993770
ep_bytes: 558bec81ec1c0100008b450c56485785
timestamp: 2011-01-06 19:15:33

Version Info:

0: [No Data]

PWS:Win32/OnLineGames.JB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Kykymber.lhMk
Elasticmalicious (moderate confidence)
DrWebTrojan.PWS.Qq.5
MicroWorld-eScanTrojan.PWS.Onlinegames.KEGA
ClamAVWin.Spyware.78845-2
FireEyeGeneric.mg.8cf6232af1978164
CAT-QuickHealTrojan.OnLineGames.gen
SkyhighBehavesLike.Win32.PWSOnlineGames.nt
McAfeePWS-OnlineGames.ke
ZillyaTrojan.Kykymber.Win32.1714
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/Kykymber.d229217a
K7GWPassword-Stealer ( 0018a90c1 )
K7AntiVirusTrojan ( 004bcce41 )
ArcabitTrojan.PWS.Onlinegames.KEGA
BitDefenderThetaAI:Packer.8556448620
VirITTrojan.Win32.Agent.DMI
SymantecInfostealer.Gampass
ESET-NOD32a variant of Win32/PSW.Kykymber.AA
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Kykymber.dpkl
BitDefenderTrojan.PWS.Onlinegames.KEGA
NANO-AntivirusTrojan.Win32.OnLineGames.bkxdd
AvastWin32:OnLineGames-FUZ [Trj]
TencentTrojan.PSW.Win32.MiBao.a
EmsisoftTrojan.PWS.Onlinegames.KEGA (B)
F-SecureTrojan.TR/Spy.OnlineGame.AC
BaiduWin32.Trojan-PSW.OLGames.b
VIPRETrojan.PWS.Onlinegames.KEGA
TrendMicroTSPY_KYMBER.SMA
Trapminemalicious.high.ml.score
SophosMal/PWS-GZ
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PSW.Kykymber.ahd
WebrootW32.Malware.Gen
AviraTR/Spy.OnlineGame.AC
MAXmalware (ai score=100)
Antiy-AVLTrojan[PSW]/Win32.Kykymber.aa
Kingsoftmalware.kb.a.1000
XcitiumPacked.Win32.MUPX.Gen@24tbus
MicrosoftPWS:Win32/OnLineGames.JB
ViRobotTrojan.Win32.A.PSW-Kykymber.97432.HX
ZoneAlarmTrojan-PSW.Win32.Kykymber.dpkl
GDataWin32.Trojan-Spy.OnlineGames.N
VaristW32/OnlineGames.FL.gen!Eldorado
AhnLab-V3Win-Trojan/Onlinegamehack37.Gen
Acronissuspicious
VBA32BScope.TrojanPSW.Kykymber
ALYacTrojan.PWS.Onlinegames.KEGA
Cylanceunsafe
PandaTrj/Kykymber.A
TrendMicro-HouseCallTSPY_KYMBER.SMA
RisingStealer.Kykymber!1.A598 (CLASSIC)
YandexTrojan.GenAsa!UpIKAaWn7QA
IkarusTrojan-PWS.Win32.Kykymber
MaxSecurenot-a-virus-PSW-OnlineGames.Gen
FortinetW32/Onlinegames.XQB!tr
AVGWin32:OnLineGames-FUZ [Trj]
DeepInstinctMALICIOUS

How to remove PWS:Win32/OnLineGames.JB?

PWS:Win32/OnLineGames.JB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment