Malware

PWS:WinNT/OnLineGames.D information

Malware Removal

The PWS:WinNT/OnLineGames.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:WinNT/OnLineGames.D virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine PWS:WinNT/OnLineGames.D?


File Info:

name: D2868CEA4B8C961B9D84.mlw
path: /opt/CAPEv2/storage/binaries/188979d819b2f384acc37636387177e602c3fc153e3c385a41c6d0ea5a1102a4
crc32: 22268157
md5: d2868cea4b8c961b9d846b175251919f
sha1: 04e825a29392c0aa9bbf0dd2af212de881c15015
sha256: 188979d819b2f384acc37636387177e602c3fc153e3c385a41c6d0ea5a1102a4
sha512: 8da7be8b8099a430d37317277b487dce1ef9945739e37737a7b39cee9c7dbf659acd5259a69b6a53435ae2be781f653ac17f0236eab1392705d3242da127088c
ssdeep: 192:HC4+9s2QQUuMnh1KDBvVzlbz59vim7D8y6U+7IA7GrmGcWv+/Hk:i4+0cMh4djn59v3EyuvymG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14B825BB22F621070D075067D5B252531317FFA7434779A9F4AE482ACAAB9F28F46C307
sha3_384: 483b0e26b12b41a1c331727d84e0c1bf51d239ad47a5e056689b41001fa43a55922bf8a545aac97790e82a1dcade77ed
ep_bytes: 558bec81ec640c00005356576a0759be
timestamp: 2012-08-23 15:16:45

Version Info:

0: [No Data]

PWS:WinNT/OnLineGames.D also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.liON
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Malware.Pf.A9F3FA2E
ClamAVWin.Trojan.Agent-585320
FireEyeGeneric.mg.d2868cea4b8c961b
CAT-QuickHealPWS.OnLineGames.MY65
SkyhighPWS-OnlineGames.lf
ALYacGeneric.Malware.Pf.A9F3FA2E
Cylanceunsafe
ZillyaTrojan.Mapler.Win32.136
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 003fb3a61 )
AlibabaTrojanPSW:Win32/OnLineGames.8d6080f2
K7GWTrojan ( 003fb3a61 )
CrowdStrikewin/malicious_confidence_90% (D)
VirITTrojan.Win32.OnlineGames4.TSH
SymantecHacktool.Rootkit
ESET-NOD32Win32/PSW.OnLineGames.QDG
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Malware.Pf.A9F3FA2E
NANO-AntivirusTrojan.Win32.Gamania.bbwhxw
AvastWin32:OnLineGames-GJK [Spy]
TencentMalware.Win32.Gencirc.13af9e49
EmsisoftGeneric.Malware.Pf.A9F3FA2E (B)
BaiduWin32.Trojan-PSW.OLGames.bx
F-SecureTrojan.TR/Crypt.ZPACK.Gen7
DrWebTrojan.PWS.Gamania.37659
VIPREGeneric.Malware.Pf.A9F3FA2E
TrendMicroTSPY_ONLINEGAMES_BK08335B.TOMC
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGeneric.Malware.Pf.A9F3FA2E
JiangminTrojan/Generic.ajnvp
WebrootW32.Malware.Gen
VaristW32/Onlinegames.RBWT-6680
AviraTR/Crypt.ZPACK.Gen7
Antiy-AVLTrojan[PSW]/Win32.Mapler
KingsoftWin32.Trojan.Generic.a
XcitiumTrojWare.Win32.Rootkit.Agent.CJT@4pr3xr
ArcabitGeneric.Malware.Pf.A9F3FA2E
ViRobotTrojan.Win32.A.PSW-Mapler.18816
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:WinNT/OnLineGames.D
GoogleDetected
AhnLab-V3Trojan/Win32.OnlineGameHack.R35589
McAfeePWS-OnlineGames.lf
MAXmalware (ai score=100)
PandaGeneric Malware
TrendMicro-HouseCallTSPY_ONLINEGAMES_BK08335B.TOMC
RisingStealer.OnlineGames!1.66AA (CLASSIC)
YandexTrojan.GenAsa!b2dK89Wag0Q
IkarusTrojan-PWS.WinNT.OnLineGames
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GamerPWS.C!tr
AVGWin32:OnLineGames-GJK [Spy]
DeepInstinctMALICIOUS

How to remove PWS:WinNT/OnLineGames.D?

PWS:WinNT/OnLineGames.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment