Malware

PWS:Win32/OnLineGames.JD.dll removal tips

Malware Removal

The PWS:Win32/OnLineGames.JD.dll is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/OnLineGames.JD.dll virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine PWS:Win32/OnLineGames.JD.dll?


File Info:

name: B9D942738684DB742959.mlw
path: /opt/CAPEv2/storage/binaries/f02203fef60c667412f87b74e229658f1ffb4c3c62bd3516efbbae4acd9b2c55
crc32: C186F58D
md5: b9d942738684db742959917478e8f39c
sha1: 94adc31d92f5bfcda48b3c17953e1d1b104939b7
sha256: f02203fef60c667412f87b74e229658f1ffb4c3c62bd3516efbbae4acd9b2c55
sha512: fcf3b6d3fe1adf4678c5b3584c5c3bbb9c6e136abe5c02980a65cec8814fae5a4cbbd086b43e3246f3972c1594248be50ed9de8d6418284fe473dae1aae4e629
ssdeep: 384:cyLXS5E7IvB27xEJCiENxTw9KPypgcyjkeHuxLifRf6v6S69MWHYS77Y9NwH:c6Evs7SJJEXwUgLyxuxOlIAYG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T103B2D0365E8C6DACE22E92FDC8619122E24430DA17F26D43538C44E6FD63660243F6B3
sha3_384: 12c28ca4c0e50b4ddd4722afcbe1e82dc2e1fe2b7ba7d805460a6dfa56bd555c5b431e6a756f2f39d7b7ff067555bb69
ep_bytes: 555d81c4000300003e833c04027c0c81
timestamp: 2010-06-26 16:17:24

Version Info:

0: [No Data]

PWS:Win32/OnLineGames.JD.dll also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
SkyhighBehavesLike.Win32.RAHack.mc
ALYacGen:Variant.Fragtor.114729
Cylanceunsafe
ZillyaTrojan.Agent.Win32.798549
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0015e4f11 )
BitDefenderGen:Variant.Fragtor.114729
K7GWRiskware ( 0015e4f11 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.FAP
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
AlibabaBackdoor:Win32/OnLineGames.f54083ff
NANO-AntivirusTrojan.Win32.MlwGen.ijcme
MicroWorld-eScanGen:Variant.Fragtor.114729
AvastWin32:Dogkild-B [Wrm]
TencentWin32.Trojan.Generic.Icnw
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.Packed.960
VIPREGen:Variant.Fragtor.114729
FireEyeGeneric.mg.b9d942738684db74
EmsisoftGen:Variant.Fragtor.114729 (B)
SentinelOneStatic AI – Malicious PE
JiangminHeur:Trojan/JunkCode
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Agent
KingsoftWin32.Trojan.Agent.deuu
MicrosoftPWS:Win32/OnLineGames.JD.dll
XcitiumVirus.Win32.Vampiro.~B@1pwxlv
ArcabitTrojan.Fragtor.D1C029
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Fragtor.114729
VaristW32/Troj_Obfusc.N.gen!Eldorado
AhnLab-V3Trojan/Win32.Agent.C168713
McAfeePWS-OnlineGames.hl.gen.d
VBA32Trojan-Injector.In-Explorer.121105
MalwarebytesMalware.AI.2270609167
PandaTrj/CI.A
RisingTrojan.Generic@AI.87 (RDML:JDkCuslGgWw2iMhF5Z0egw)
YandexTrojan.Kryptik!tQ1jclBkFxY
IkarusVirus.Win32.Dogkild
MaxSecureTrojan.Malware.877459.susgen
FortinetW32/OnlineGames_hl.D!tr.pws
BitDefenderThetaAI:Packer.A773B5CF1E
AVGWin32:Dogkild-B [Wrm]
Cybereasonmalicious.d92f5b
DeepInstinctMALICIOUS

How to remove PWS:Win32/OnLineGames.JD.dll?

PWS:Win32/OnLineGames.JD.dll removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment