W32/Onlinegames.2!Generic
W32/Onlinegames.2!Generic installs itself to the system by copying its file to Windows folder. It also creates a startup key value in the Registry for the copied file.,After installation the trojan locates the Explorer.exe process, drops a DLL from its body onto a hard drive and injects the dropped DLL into the Windows Explorer process. Note that unlike the main trojan’s file, the DLL is dropped into the Windows System folder. The dropped DLL is the main spying component. It contains the encrypted URL that is used to send stolen data. The stolen data is sent to a hacker by accessing the specified website with a specially constructed URL. The trojan can also try to connect to a hard-coded IP Address, create a socket and send stolen data to it. virus file kncex32.exe,kncel32.dll, kncex32.ini msiffei.sys
cleanog.exe
Need help? Post you problem on Free Malware Remove Help forum
W32/Onlinegames.2!Generic Summary
1.Temporarily Disable System Restore;2.Reboot computer in SafeMode;3.delte W32/Onlinegames.2!Generic virus files and kill W32/Onlinegames.2!Generic file task process(if have);4.Delete/Modify any values added to the registry by W32/Onlinegames.2!Generic ;5.delete IE temp files,restart the computer and run a whole scan with F-Prot6. W32/Onlinegames.2!Generic virus files as following: