Malware

Should I remove “Win32/PSW.OnLineGames.NSU”?

Malware Removal

The Win32/PSW.OnLineGames.NSU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSW.OnLineGames.NSU virus can do?

  • At least one process apparently crashed during execution
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality

How to determine Win32/PSW.OnLineGames.NSU?


File Info:

name: 2B3EB89E9CEBA23B3216.mlw
path: /opt/CAPEv2/storage/binaries/f4ae7183ee78a6b03793ac5dec4e19d561b6f94fdb4975d83a4ef0bfb4293b2d
crc32: 2347E88F
md5: 2b3eb89e9ceba23b3216997234b7293f
sha1: b2328e6f361a1ba4a49cf1d753a06ab49fa545e5
sha256: f4ae7183ee78a6b03793ac5dec4e19d561b6f94fdb4975d83a4ef0bfb4293b2d
sha512: 57c77405329d01649b23248e51437eabd0cb1f48157e11b74dcbdf49acc1776f5d5e5ea4ad4ada4c2022e3014752a04865a95bc94e8cc1a1a3fe498d039b297b
ssdeep: 768:3bLUFkCYuXE716jZwlsSviqUpcnKi1aSQOgyqoAyAKhKnVwC/yQiLOsDniS0zuRS:buXE7eSqneKifgyrAJKdHCsu+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17704F1C78C35D4EBC32B46B994A40C157CFB101EDCB9E16897936EE0A9F369E0990E47
sha3_384: 17c17723180753f6ef2bca41c0d5d3fc504cf3e9b1e78cf7686da755b5db10af80f1946b9459533ce3e2fbd5acb8b00a
ep_bytes: e85afaffff682c3040006800100000e8
timestamp: 2004-01-23 23:39:42

Version Info:

0: [No Data]

Win32/PSW.OnLineGames.NSU also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Wsgame.23258
MicroWorld-eScanDropped:Trojan.Cridex.Gen.1
FireEyeGeneric.mg.2b3eb89e9ceba23b
ALYacDropped:Trojan.Cridex.Gen.1
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 003b1b581 )
K7GWTrojan ( 003b1b581 )
Cybereasonmalicious.e9ceba
BitDefenderThetaAI:Packer.622456FF1C
CyrenW32/Heuristic-166!Eldorado
SymantecDownloader
ESET-NOD32a variant of Win32/PSW.OnLineGames.NSU
APEXMalicious
KasperskyTrojan-Dropper.Win32.Small.dat
BitDefenderDropped:Trojan.Cridex.Gen.1
NANO-AntivirusTrojan.Win32.Qhost.xdeem
AvastWin32:Trojan-gen
RisingTrojan.Generic@AI.96 (RDMK:cmRtazoZuWi++A28kO7wrjArH1PZ)
Ad-AwareDropped:Trojan.Cridex.Gen.1
SophosMal/Generic-R
ComodoTrojWare.Win32.TrojanDropper.Samll.~A@adf8z
F-SecureTrojan.TR/Dropper.Gen
McAfee-GW-EditionBehavesLike.Win32.HLLP.cz
EmsisoftDropped:Trojan.Cridex.Gen.1 (B)
IkarusTrojan.SuspectCRC
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
Antiy-AVLGrayWare/Win32.Kryptik.ffp
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Cridex.Gen.1
ZoneAlarmTrojan-Dropper.Win32.Small.dat
GDataDropped:Trojan.Cridex.Gen.1
CynetMalicious (score: 100)
McAfeeRDN/Generic Dropper
VBA32Heur.Trojan.Hlux
MalwarebytesMalware.Heuristic.1003
YandexTrojan.GenAsa!0cMxEzVIdGU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.W32.Packer.Upack0.3.9
FortinetW32/OnLineGames.NSU!tr.pws
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/PSW.OnLineGames.NSU?

Win32/PSW.OnLineGames.NSU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment