Trojan

Trojan.PWS.Onlinegames.KEGA malicious file

Malware Removal

The Trojan.PWS.Onlinegames.KEGA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.PWS.Onlinegames.KEGA virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.PWS.Onlinegames.KEGA?


File Info:

name: 1661B774CFF46EE4CFD9.mlw
path: /opt/CAPEv2/storage/binaries/aaa87e4448652d8c3aa7323e672a1e05657c94f42902e0d6b75c5cf3d204df22
crc32: 4C333E90
md5: 1661b774cff46ee4cfd9fb2fa74bf2a0
sha1: 45ec4d235dec53570b476a867cda6432a47b1939
sha256: aaa87e4448652d8c3aa7323e672a1e05657c94f42902e0d6b75c5cf3d204df22
sha512: 2970459b9592afa44e2aa4898a2b3925bd1616d3483bf73e231433701b67f182d217e3d23d2a2ba6cac968dcc89ffb67536994559cbd37344a7f83ffa8120c66
ssdeep: 1536:n7ZLNPp9pZBMx2CP/RIteqwKp/Yv3vEMTbWwTGNjARhczzCoZQ:7Zppy2TTwK6vpKwT1zizCoZQ
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1B363C0A0DD2F7179E76FDA7B89AA7C38891533FB7E43D58B203551812176181AF0312E
sha3_384: cb9bd846c209f47040d8923e59c4440519ab834d082cfe6a2d63f80d0ec803826f984b2f4fbde5b0d02979dde844505d
ep_bytes: 807c2408010f85b901000060be009000
timestamp: 2011-03-02 13:46:07

Version Info:

0: [No Data]

Trojan.PWS.Onlinegames.KEGA also known as:

BkavW32.FamVT.Kykymber.P.Trojan
DrWebTrojan.PWS.Qq.5
MicroWorld-eScanTrojan.PWS.Onlinegames.KEGA
FireEyeGeneric.mg.1661b774cff46ee4
CAT-QuickHealTrojan.OnLineGames.gen
SkyhighBehavesLike.Win32.PWSOnlineGames.km
McAfeePWS-OnlineGames.ke
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kykymber.Win32.5676
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanPSW:Win32/Kykymber.394bd4de
K7GWTrojan ( 0037c4831 )
K7AntiVirusTrojan ( 0037c4831 )
BitDefenderThetaAI:Packer.8E947EBE20
VirITTrojan.Win32.Generic.BBRX
SymantecInfostealer.Gampass
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/PSW.Kykymber.AA
APEXMalicious
TrendMicro-HouseCallTSPY_KYMBER.SMDV
ClamAVWin.Trojan.Agent-365609
KasperskyTrojan-PSW.Win32.Kykymber.dpsd
BitDefenderTrojan.PWS.Onlinegames.KEGA
NANO-AntivirusTrojan.Win32.OnLineGames.bkxdd
AvastWin32:Trojan-gen
TencentTrojan.PSW.Win32.MiBao.a
TACHYONTrojan-PWS/W32.Kykymber.80908.B
EmsisoftTrojan.PWS.Onlinegames.KEGA (B)
F-SecureTrojan.TR/Spy.Gen
BaiduWin32.Trojan-PSW.Kykymber.a
VIPRETrojan.PWS.Onlinegames.KEGA
TrendMicroTSPY_KYMBER.SMDV
Trapminemalicious.moderate.ml.score
SophosMal/PWS-GZ
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.dnro
GoogleDetected
AviraTR/Spy.Gen
VaristW32/OnlineGames.FL.gen!Eldorado
Antiy-AVLTrojan[PSW]/Win32.Kykymber
Kingsoftmalware.kb.b.969
MicrosoftPWS:Win32/OnLineGames!pz
XcitiumTrojWare.Win32.PSW.GamePass.F@35ift2
ArcabitTrojan.PWS.Onlinegames.KEGA
ViRobotTrojan.Win32.A.PSW-Kykymber.76084[UPX]
ZoneAlarmTrojan-PSW.Win32.Kykymber.dpsd
GDataWin32.Trojan-Spy.OnlineGames.N
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/OnlineGameHack45.Gen
Acronissuspicious
VBA32BScope.TrojanPSW.QQPass
ALYacTrojan.PWS.Onlinegames.KEGA
MAXmalware (ai score=100)
Cylanceunsafe
PandaTrj/Kykymber.A
RisingStealer.QQPass!1.659F (CLASSIC)
YandexTrojan.GenAsa!zT5/8dn9vmo
IkarusTrojan-PWS.Win32.OnLineGames
MaxSecurenot-a-virus-PSW-OnlineGames.Gen
FortinetW32/Onlinegames.XQB!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
alibabacloudTrojan[spy]:Win/Kykymber.AA

How to remove Trojan.PWS.Onlinegames.KEGA?

Trojan.PWS.Onlinegames.KEGA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment