Trojan

TrojanPSW.OnLineGames.a malicious file

Malware Removal

The TrojanPSW.OnLineGames.a is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanPSW.OnLineGames.a virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary file triggered YARA rule
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanPSW.OnLineGames.a?


File Info:

name: 1D68649A8B4E1BB2D63A.mlw
path: /opt/CAPEv2/storage/binaries/6301adb4109cbf171d12abb05adc108aecd79a3b867176af369c1a3a15a39f8d
crc32: 1F6CA0B7
md5: 1d68649a8b4e1bb2d63a90203ffd210d
sha1: 43bb1a438ca67ac9c13d907e550c70945897b993
sha256: 6301adb4109cbf171d12abb05adc108aecd79a3b867176af369c1a3a15a39f8d
sha512: a01a76c6a40c25ce5b435ff9f16a520548bceae6aded78259529f6707f7e873e324f25c7bf89734b4dc20634c5afa0fab3b5e5013d974b8c4cb10cdc925cab3f
ssdeep: 12288:/CTCzLhV9Ro96N2xqZ4iECBTVAqfSHzv8x0/gvJapz:/p7696N2oZxBuqqrUUgvJO
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T163B4DF683ABDD436CA0E1BF529AD97C866F790279F02C31F790C461E7D79666A803334
sha3_384: 0d5eaea4cbe9b1a540fd5e29077b4c7abdc04a0bf1c8f66a5e201e4a5e0fe444221a1b410077ad2e8bec9ea13b8107ac
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2005-06-07 06:03:45

Version Info:

CompanyName:
FileDescription:
FileVersion: 1, 0, 0, 1
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1, 0, 0, 1
Translation: 0x0804 0x04b0

TrojanPSW.OnLineGames.a also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.OnLineGames.mugb
SkyhighBehavesLike.Win32.Generic.gc
McAfeeArtemis!1D68649A8B4E
SangforPUP.Win32.FlyStudio.Vw3r
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
SophosGeneric Reputation PUA (PUA)
Antiy-AVLGrayWare/Win32.Presenoker
MicrosoftPUA:Win32/Presenoker
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
GDataWin32.Application.FlyStudio.L
CynetMalicious (score: 100)
VBA32TrojanPSW.OnLineGames.a
Cylanceunsafe
MaxSecureTrojan.Malware.121218.susgen
FortinetRiskware/Application
DeepInstinctMALICIOUS

How to remove TrojanPSW.OnLineGames.a?

TrojanPSW.OnLineGames.a removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment