Malware

What is “Win32/PSW.OnLineGames.POT”?

Malware Removal

The Win32/PSW.OnLineGames.POT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSW.OnLineGames.POT virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/PSW.OnLineGames.POT?


File Info:

name: C269DC29E5A2531E1B34.mlw
path: /opt/CAPEv2/storage/binaries/5fcac7aed237a85105a32bf7c150924e3d778b0094b699f5612516d71bf5a296
crc32: 649ED2D6
md5: c269dc29e5a2531e1b34bff1d67c5d64
sha1: 1bc920ccc00b960e6294540d7e7300a41da5290b
sha256: 5fcac7aed237a85105a32bf7c150924e3d778b0094b699f5612516d71bf5a296
sha512: 8ac33f3997043c582df8c1e56f2ca33baf13064bec2851931e9733daf6bbdb6f06b959c15926e32a48dc0aa1f0d0d5f29183d06cd4c611eae2c1cd0e58bec38f
ssdeep: 3072:l9L1xm6hpbVc+Nn0/d/Q4nDlKPQgO1f5Q:hnhpprNn8o4URif5Q
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T100C3AE9863895A7AE32E8437549A3F37153E31F399D7501B433202A528BE5C1BF0EE5B
sha3_384: fb242324b8d66e25c3e2c2ffd5c4429fcb2225ca50d2904a0be684f8b19d9f06308143193887978d4cebccac956e1873
ep_bytes: 558bec81ec1c0100008b450c56485785
timestamp: 2011-01-11 12:22:19

Version Info:

0: [No Data]

Win32/PSW.OnLineGames.POT also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Kykymber.lhMk
AVGWin32:OnLineGames-FUZ [Trj]
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.PWS.Onlinegames.KEGA
FireEyeGeneric.mg.c269dc29e5a2531e
CAT-QuickHealTrojan.OnLineGames.gen
SkyhighBehavesLike.Win32.PWSOnlineGames.ct
ALYacTrojan.PWS.Onlinegames.KEGA
Cylanceunsafe
ZillyaTrojan.Kykymber.Win32.1662
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojanPSW:Win32/OnLineGames.8fd23338
K7GWTrojan ( 0056e0a61 )
BaiduWin32.Trojan-PSW.Kykymber.a
VirITTrojan.Win32.Generic.XK
SymantecInfostealer.Gampass
ESET-NOD32a variant of Win32/PSW.OnLineGames.POT
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:OnLineGames-FUZ [Trj]
ClamAVWin.Spyware.78845-2
KasperskyTrojan-PSW.Win32.Kykymber.dppu
BitDefenderTrojan.PWS.Onlinegames.KEGA
NANO-AntivirusTrojan.Win32.OnLineGames.bkxdd
TencentTrojan.PSW.Win32.MiBao.a
EmsisoftTrojan.PWS.Onlinegames.KEGA (B)
F-SecureTrojan.TR/PSW.Kykymber.kxk
DrWebTrojan.PWS.Qq.5
VIPRETrojan.PWS.Onlinegames.KEGA
TrendMicroTSPY_KYMBER.SMA
Trapminemalicious.high.ml.score
SophosMal/PWS-GZ
GDataWin32.Trojan-Spy.OnlineGames.N
WebrootW32.Malware.Gen
VaristW32/OnlineGames.FL.gen!Eldorado
AviraTR/PSW.Kykymber.kxk
MAXmalware (ai score=100)
Antiy-AVLTrojan[PSW]/Win32.Kykymber.aa
KingsoftWin32.PSWTroj.Undef.a
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.PWS.Onlinegames.KEGA
ViRobotTrojan.Win32.A.PSW-Kykymber.126912.AE
ZoneAlarmTrojan-PSW.Win32.Kykymber.dppu
MicrosoftPWS:Win32/OnLineGames.IZ
GoogleDetected
AhnLab-V3Win-Trojan/Onlinegamehack37.Gen
Acronissuspicious
McAfeePWS-OnlineGames.ke
VBA32BScope.TrojanPSW.Kykymber
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Kykymber.A
TrendMicro-HouseCallTSPY_KYMBER.SMA
RisingStealer.QQPass!1.659F (CLASSIC)
YandexTrojan.PWS.Kykymber!Fd1N5fQcaH4
IkarusTrojan-PWS.Win32.Kykymber
MaxSecurenot-a-virus-PSW-OnlineGames.Gen
FortinetW32/Onlinegames.XQB!tr
BitDefenderThetaGen:NN.ZedlaF.36804.hm7@a0bxCwm
DeepInstinctMALICIOUS
alibabacloudRiskWare:Win/OnLineGames.POT

How to remove Win32/PSW.OnLineGames.POT?

Win32/PSW.OnLineGames.POT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment