Trojan

Trojan.PWS.OnLineGames.SSH removal guide

Malware Removal

The Trojan.PWS.OnLineGames.SSH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.PWS.OnLineGames.SSH virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.PWS.OnLineGames.SSH?


File Info:

name: DFBCF28FF246F098F065.mlw
path: /opt/CAPEv2/storage/binaries/57f83280132e8792400907997ac365c927619ee6d868c62312dc61b2d22640ee
crc32: 94F4C3DC
md5: dfbcf28ff246f098f065a6dd519cca84
sha1: ce950d942a7deb4bdf27ad976345f3239b7639f7
sha256: 57f83280132e8792400907997ac365c927619ee6d868c62312dc61b2d22640ee
sha512: 5c7f6b553aa935a320bcaa4c30371d4cc604889e9d2c895165c4ab5f02f4e376740369d79fe0dbcae155fedeb9e37f3cf467455ffa9c8d9b79aec792743f5957
ssdeep: 3072:NtM4DPAE+CQ4c//////TRUmdYFGTZevnMlIOItQRay5UngREmAMOndgMeVev:N2DE+r4c//////5dKU8vnMlIOItJYRtu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15804D00B9660E872D95026BACD1A96FE45263E70FC4A54473AF6FF0EFD79380122C653
sha3_384: 19f15164c3eb80289bfbd64248fa3850b5aa5e1e4696792aa69ee413474368fc423912cae1538df9a75d863ff1355c15
ep_bytes: 558bec83c4f0b87ca1000ee834a4ffff
timestamp: 1970-01-14 10:02:38

Version Info:

0: [No Data]

Trojan.PWS.OnLineGames.SSH also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.PWS.OnLineGames.SSH
FireEyeGeneric.mg.dfbcf28ff246f098
ALYacTrojan.PWS.OnLineGames.SSH
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 003b1b581 )
K7AntiVirusTrojan ( 003b1b581 )
ArcabitTrojan.PWS.OnLineGames.SSH
BitDefenderThetaAI:Packer.75A292FB1D
CyrenW32/KillAV.B.gen!Eldorado
SymantecBackdoor.Trojan
ESET-NOD32a variant of Win32/TrojanDropper.Delf.NJA
APEXMalicious
KasperskyUDS:Trojan-Dropper.Win32.Agent.xkh
BitDefenderTrojan.PWS.OnLineGames.SSH
NANO-AntivirusTrojan.Win32.OnLineGames.ldyi
AvastWin32:Atraps-EI [Trj]
Ad-AwareTrojan.PWS.OnLineGames.SSH
SophosMal/Generic-R
ComodoBackdoor.Win32.Delf.~DD@1mio8w
DrWebTrojan.PWS.Gamania.16189
TrendMicroTSPY_GAMETHI.C
McAfee-GW-EditionBehavesLike.Win32.HLLPPhilis.ch
EmsisoftTrojan.PWS.OnLineGames.SSH (B)
JiangminHeur:Trojan/Delf
AviraDR/Delphi.Gen
Antiy-AVLTrojan/Generic.ASMalwS.76B9FB
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmTrojan-GameThief.Win32.OnLineGames.tlyx
GDataTrojan.PWS.OnLineGames.SSH
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.OnLineGames.C5101133
McAfeeGenericRXAA-AA!DFBCF28FF246
MAXmalware (ai score=80)
VBA32BScope.TrojanPSW.Gamania
TrendMicro-HouseCallTSPY_GAMETHI.C
RisingTrojan.Generic@AI.99 (RDMK:cmRtazr4+vvKXkMtz0PgaTcwUkgo)
YandexTrojan.GenAsa!1lao6WahX+M
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.W32.Packer.Upack0.3.9
FortinetW32/Delf.NJA!tr
AVGWin32:Atraps-EI [Trj]

How to remove Trojan.PWS.OnLineGames.SSH?

Trojan.PWS.OnLineGames.SSH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment