W32/Onlinegames.2!Generic



W32/Onlinegames.2!Generic installs itself to the system by copying its file to Windows folder. It also creates a startup key value in the Registry for the copied file.,After installation the trojan locates the Explorer.exe process, drops a DLL from its body onto a hard drive and injects the dropped DLL into the Windows Explorer process. Note that unlike the main trojan’s file, the DLL is dropped into the Windows System folder. The dropped DLL is the main spying component. It contains the encrypted URL that is used to send stolen data. The stolen data is sent to a hacker by accessing the specified website with a specially constructed URL. The trojan can also try to connect to a hard-coded IP Address, create a socket and send stolen data to it. virus file kncex32.exe,kncel32.dll, kncex32.ini msiffei.sys
cleanog.exe

Tags:

Need help? Post you problem on Free Malware Remove Help forum


W32/Onlinegames.2!Generic Summary

  • Virus Name:W32/Onlinegames.2!Generic
  • Detected By:F-Prot6 antivirus program
  • Virus W32/Onlinegames.2!Generic Detected times:235811times
  • W32/Onlinegames.2!Generic Overall Risk:Medium 735812
  • W32/Onlinegames.2!Generic file size:3658120 bytes
  • W32/Onlinegames.2!Genericwas first Detected by F-Prot6 on Friday, August 29th, 2008 , 3:27 am,W32/Onlinegames.2!Generic is a new threats of Hacking,Malware,Spam,worm.
  • Remove W32/Onlinegames.2!Generic instruction:

  • 1.Temporarily Disable System Restore;2.Reboot computer in SafeMode;3.delte W32/Onlinegames.2!Generic virus files and kill W32/Onlinegames.2!Generic file task process(if have);4.Delete/Modify any values added to the registry by W32/Onlinegames.2!Generic ;5.delete IE temp files,restart the computer and run a whole scan with F-Prot6. W32/Onlinegames.2!Generic virus files as following:

    Leave a Reply