Threat Descriptons



Category :


Type :



The file detected as Trojan-PSW.Win32.OnLineGames.JCT drops another trojan that is detected as Trojan-Downloader.Win32.Agent.BLM.


Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.

A False Positive is when a file is incorrectly detected as harmful, usually because its code or behavior resembles known harmful programs. A False Positive will usually be fixed in a subsequent database update without any action needed on your part. If you wish, you may also:

  • Check for the latest database updates

    First check if your F-Secure security program is using the latest updates, then try scanning the file again.

  • Submit a sample

    After checking, if you still believe the file is incorrectly detected, you can submit a sample of it for re-analysis.

    Note: If the file was moved to quarantine, you need to collect the file from quarantine before you can submit it.

  • Exclude a file from further scanning

    If you are certain that the file is safe and want to continue using it, you can exclude it from further scanning by the F-Secure security product.

    Note: You need administrative rights to change the settings.

Technical Details

On execution, files detected as Trojan-PSW.Win32.OnLineGames.jct will modify the access rights for the file named %windir%\system32\drivers\pcihdd.sys. It then deletes pcihdd.sys.It drops a file called that is detected as Trojan-Downloader.Win32.Agent.blm.Note: %windir% typically refers to the C:\Windows folder.The file will drop a new file using the name pcihdd.sys that is detected as Trojan-Downloader.Win32.Agent.blm. It drops the file to the windows system folder and creates the following registry entry to start as a service:

  • HKLM\System\CurrentControlSet\Services\PciHdd ImagePath = \??\C:\WINDOWS\system32\drivers\pcihdd.sys

OnlineGames.JCT may also attempt to load files from the following URLs:

  • http://[REMOVED]
  • http://[REMOVED]

The sites were offline during our investigations.The file pcihdd.sys will attempt to download and parse a file from this URL:


At the time of investigation, the said file contains a link to another malware that is detected as Worm.Win32.Agent.y.

More Support


Ask questions in our Community .

User Guides

Check the user guide for instructions.

Contact Support

Chat with or call an expert.

Submit a Sample

Submit a file or URL for analysis.