Threat Database Viruses Spyware.OnlineGames

Spyware.OnlineGames

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 1
First Seen: July 24, 2009
OS(es) Affected: Windows

Spyware.OnlineGames is a computer virus. Once Spyware.OnlineGames is inside a system it will target sensitive information such as online game passwords, usernames and login details. Spyware.OnlineGames will monitor a victim's internet activities and cause the system to deteriorate in performance. Remove this privacy threat from your PC as soon as you detect it.

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Panda Trj/Genetic.gen
AVG PSW.OnlineGames3.DEF
Sophos Mal/EncPk-IE
Kaspersky Trojan-GameThief.Win32.Taworm.hhl
ClamAV Trojan.OnlineGames-6080
K7AntiVirus Trojan
McAfee PWS-Gamania.gen.k
Panda Trj/Lineage.KSJ
AVG PSW.OnlineGames3.AWA
AntiVir TR/PSW.Frethog.S
F-Secure Trojan-PSW:W32/OnlineGames.gen!E
Comodo Packed.Win32.MNSP.Gen
Kaspersky Trojan-GameThief.Win32.OnLineGames.bluw
ClamAV Trojan.Onlinegames-6069
Symantec Trojan.Packed.NsAnti

SpyHunter Detects & Remove Spyware.OnlineGames

File System Details

Spyware.OnlineGames may create the following file(s):
# File Name MD5 Detections
1. ss12C705dll.dll e0130a2434f4e8286ba1ccebdb50abae 1
2. C:\System Volume Information\_restore{41F3C0EE-8C38-4C01-B6B0-4D388DDB8F47}\RP31\A0041531.dll
3. C:\System Volume Information\_restore{41F3C0EE-8C38-4C01-B6B0-4D388DDB8F47}\RP31\A0041513.sys
4. C:\System Volume Information\_restore{41F3C0EE-8C38-4C01-B6B0-4D388DDB8F47}\RP29\A0039422.sys
5. C:\System Volume Information\_restore{41F3C0EE-8C38-4C01-B6B0-4D388DDB8F47}\RP31\A0041545.dll
6. C:\Documents and Settings\\Local Settings\Temp\03.cab
7. C:\Documents and Settings\\Local Settings\Temporary Internet Files\Content.IE5\85I3GLEJ\03[1].cab
8. C:\System Volume Information\_restore{41F3C0EE-8C38-4C01-B6B0-4D388DDB8F47}\RP29\A0039329.sdb
9. C:\System Volume Information\_restore{41F3C0EE-8C38-4C01-B6B0-4D388DDB8F47}\RP31\A0040509.ttf
10. C:\System Volume Information\_restore{41F3C0EE-8C38-4C01-B6B0-4D388DDB8F47}\RP31\A0041533.sdb
11. C:\System Volume Information\_restore{41F3C0EE-8C38-4C01-B6B0-4D388DDB8F47}\RP32\A0043854.ttf
12. C:\System Volume Information\_restore{41F3C0EE-8C38-4C01-B6B0-4D388DDB8F47}\RP32\A0043951.sdb
13. C:\WINDOWS\AppPatch\AcXtrnel.sdb
14. C:\Documents and Settings\\Local Settings\Temp\24.cab
15. C:\System Volume Information\_restore{41F3C0EE-8C38-4C01-B6B0-4D388DDB8F47}\RP29\A0039328.ttf
16. C:\System Volume Information\_restore{41F3C0EE-8C38-4C01-B6B0-4D388DDB8F47}\RP31\A0039509.ttf
17. C:\System Volume Information\_restore{41F3C0EE-8C38-4C01-B6B0-4D388DDB8F47}\RP31\A0041532.ttf
18. C:\System Volume Information\_restore{41F3C0EE-8C38-4C01-B6B0-4D388DDB8F47}\RP32\A0042863.ttf
19. C:\System Volume Information\_restore{41F3C0EE-8C38-4C01-B6B0-4D388DDB8F47}\RP32\A0043950.ttf
20. C:\WINDOWS\Fonts\Framdee.ttf
21. C:\Documents and Settings\\Local Settings\Temp\23.cab
22. C:\System Volume Information\_restore{41F3C0EE-8C38-4C01-B6B0-4D388DDB8F47}\RP29\A0038327.ttf
23. C:\System Volume Information\_restore{41F3C0EE-8C38-4C01-B6B0-4D388DDB8F47}\RP29\A0039442.ttf
24. C:\System Volume Information\_restore{41F3C0EE-8C38-4C01-B6B0-4D388DDB8F47}\RP31\A0041509.ttf
25. C:\System Volume Information\_restore{41F3C0EE-8C38-4C01-B6B0-4D388DDB8F47}\RP31\A0042760.ttf
26. C:\System Volume Information\_restore{41F3C0EE-8C38-4C01-B6B0-4D388DDB8F47}\RP32\A0043893.ttf
27. fmbiost.dll eeba4403dd6d4c21c9dac4f299fe2392 0
28. seolof.dll 01c5a083baf0fbe40f4fdec6396efcda 0
29. tciocp64.dll a3d6098a7b07c58a29320fce5327ca70 0
30. CLADD 999186855576f34f5c5f9569ffe94fd0 0
31. CLADD e344746f13e08a3a1aaaf731a3e1a365 0
32. CLADD acbc0003c06d3ed22d0bf09951302e24 0
33. CLADD fe12c07496b7267acdb4c3033cce9163 0
34. CLADD 84274bf6c10e6df8504c1252794ec22b 0
35. CLADD fc74c741eae66be6e088033a14c92392 0
36. CLADD 4c0177b083e3c600095e4282ee17c12a 0
37. CLADD 4ab6423d7024be8b25f8fcb11273be32 0
38. CLADD 9db61d96b80de3b21a618e8f0c226541 0
39. CLADD 056098aedfd846f6b51e33dafb2901ea 0
40. CLADD 8cde6cab84441f3d70cbf784dcf3229f 0
41. CLADD fd8f90e3fb18aa78d1d99c1e668bea73 0
42. CLADD a7520b5120477af7eacbbfdad1092838 0
43. CLADD 24d41f129dfa7e7f5792c00a8b41b3a8 0
44. CLADD adec91dcc99bc375aaa232849ecbf665 0
45. liser.exe f5968a8bdf0d5eee584fbb24e826ff68 0
46. herss.exe 86b143c091bd849832ba636e53162f3c 0
47. lsass.exe 6968b88fd1fa9cf140a64c2870d67a86 0

Registry Details

Spyware.OnlineGames may create the following registry entry or registry entries:
HKEY_CLASSES_ROOT\CLSID\{12b02216-ac3f-42a7-8313-449771237061}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\9fd8db
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\5102a80
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{3474a8c2-bef9-46c8-983a-a26a0030ec30}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{b3721c07-62b3-411a-9dc7-f5f27e3e21ff}
HKEY_CLASSES_ROOT\CLSID\{d7c79813-9233-4ae0-832c-99b2e8019673}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\9fd8db
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\5102a80
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\4901228
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{12b02216-ac3f-42a7-8313-449771237061}
KEY_CLASSES_ROOT\CLSID\{3474a8c2-bef9-46c8-983a-a26a0030ec30}
HKEY_CLASSES_ROOT\CLSID\{b3721c07-62b3-411a-9dc7-f5f27e3e21ff}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\9fd8db
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\5102a80
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{d7c79813-9233-4ae0-832c-99b2e8019673}

Trending

Most Viewed

Loading...