Trojan

VHO:Trojan-GameThief.Win32.OnLineGames (file analysis)

Malware Removal

The VHO:Trojan-GameThief.Win32.OnLineGames is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Trojan-GameThief.Win32.OnLineGames virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (12 unique times)
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.

Related domains:

www.shanghai114.net
www.nanjing114.net
www.cfyouxi.com
dnspod.qcloud.com
stopnote.vhostgo.com
ocsp.digicert.cn
imgcache.qq.com
3gimg.qq.com
ocsp.globalsign.com
ocsp2.globalsign.com
sdi.3g.qq.com
hm.baidu.com

How to determine VHO:Trojan-GameThief.Win32.OnLineGames?


File Info:

crc32: 38396808
md5: d90ad612dc277edae78cac9c84305a4c
name: D90AD612DC277EDAE78CAC9C84305A4C.mlw
sha1: 90fb0d3ef410ec483da1505ab026f778a3c721c9
sha256: 1a1a52c884db7e2bfbbab88d03863633a76ec08a9a7ca96141ada86aaa4e2bb3
sha512: c5dec683fc1cb8d9a7b9a07596d2a941bfbbfc6bffa317317698b035b3a46855d5ce7d780f595f9ea409545531f9d2881637acb75bf2f37200dab731dbee0899
ssdeep: 24576:PeE0UEOPPKEwq+dGh8EFnYyYy7V4cS2uQFk0z+7E4cr:PH0EHKEwq+dbFyYy2pyk0z+Bi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x5168x80fdx8f85x52a9
FileVersion: 1.0.0.0
CompanyName: x5168x80fdx8f85x52a9
Comments: x5168x80fdx8f85x52a9
ProductName: x5168x80fdx8f85x52a9
ProductVersion: 1.0.0.0
FileDescription: x5168x80fdx8f85x52a9
Translation: 0x0804 0x04b0

VHO:Trojan-GameThief.Win32.OnLineGames also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0040f54a1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CylanceUnsafe
ZillyaTrojan.Genome.Win32.237332
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0040f54a1 )
Cybereasonmalicious.ef410e
CyrenW32/A-6b6eecbc!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan-GameThief.Win32.OnLineGames.gen
AlibabaTrojan:Win32/Flyagent.cf03af3b
NANO-AntivirusTrojan.Win32.Gendal.derrtx
TencentWin32.Risk.Packer.Wpta
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaGen:NN.ZexaF.34236.4q0@auHSpUnb
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.d90ad612dc277eda
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.A65B48
MicrosoftTrojan:Win32/Emotet!ml
Acronissuspicious
McAfeeFlyagent.d
MAXmalware (ai score=98)
MalwarebytesTrojan.MalPack.FlyStudio
PandaTrj/Genetic.gen
RisingPacker.Win32.Agent.g (CLASSIC)
YandexTrojan.GenAsa!Q4G89fRHfnI
IkarusTrojan.Win32.Sasfis
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.BELF!tr
Paloaltogeneric.ml

How to remove VHO:Trojan-GameThief.Win32.OnLineGames?

VHO:Trojan-GameThief.Win32.OnLineGames removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment