Malware

How to remove “PWS:Win32/OnLineGames.LP”?

Malware Removal

The PWS:Win32/OnLineGames.LP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/OnLineGames.LP virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Created a service that was not started

How to determine PWS:Win32/OnLineGames.LP?


File Info:

name: A1942EA672955EC05EAB.mlw
path: /opt/CAPEv2/storage/binaries/954ddcb7ed951cb4c741d3d1cef4e2f70f6e34fe21c1bb1d896b9cca92bfe5a0
crc32: 434B5D5B
md5: a1942ea672955ec05eab7639ba3db6cf
sha1: 5fabb3ac9cbc9c5da5a87d485ff4707c3b3f7eac
sha256: 954ddcb7ed951cb4c741d3d1cef4e2f70f6e34fe21c1bb1d896b9cca92bfe5a0
sha512: feef5b51ef99d88bb62d3367a8c03d3b6a83321f9ac09afd4ee2e5d3ca2564ae9969e1d945fb56f3f3c4aef4037700a159fa946be234c46fbe9ae2605a4be9a9
ssdeep: 1536:Htudd6vqSUmGwZpveEsyx8/Ou0PbuOg0p2bUgdm6:HtuuvqSUsZl7H6ONPbuOYdm6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T133A38E47774550B2C09A063022593A3B897F6C74596AADA7EFA1B4863CB10F7F639F03
sha3_384: b5429e095292136772de837a969557b6737ca0d0f2b9a53825c2eca2d09b157f0994c450777b332e4d1303c866c1855a
ep_bytes: 558bec81ec340700005356576a4033db
timestamp: 2012-02-04 12:48:21

Version Info:

0: [No Data]

PWS:Win32/OnLineGames.LP also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojanPWS.OnLineGame.LP5
ALYacGen:Variant.Doina.18762
Cylanceunsafe
ZillyaDropper.Agent.Win32.238755
SangforSuspicious.Win32.Save.ins
K7AntiVirusPassword-Stealer ( 0040f7d11 )
AlibabaTrojanPSW:Win32/OnLineGames.e63641b8
K7GWPassword-Stealer ( 0040f7d11 )
Cybereasonmalicious.672955
BaiduWin32.Trojan-Downloader.Agent.j
CyrenW32/OnLineGames.KT.gen!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/PSW.OnLineGames.QNW
APEXMalicious
ClamAVWin.Trojan.Generic-9945241-0
KasperskyTrojan-Dropper.Win32.Agent.hhwa
BitDefenderGen:Variant.Doina.18762
NANO-AntivirusTrojan.Win32.AVKill.fjemut
ViRobotTrojan.Win32.A.PSW-Kykymber.48028.C
MicroWorld-eScanGen:Variant.Doina.18762
AvastWin32:GenMalicious-HAE [Trj]
TencentTrojan.TenThief.QQPsw.bns
EmsisoftGen:Variant.Doina.18762 (B)
F-SecureHeuristic.HEUR/AGEN.1322555
DrWebTrojan.AVKill.14165
VIPREGen:Variant.Doina.18762
TrendMicroTSPY_ONLINEG.NUR
McAfee-GW-EditionBehavesLike.Win32.Generic.nm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.a1942ea672955ec0
SophosMal/PWS-AL
IkarusTrojan.Win32.VB
JiangminTrojan/Generic.sknn
WebrootW32.Trojan.Gen
AviraTR/Kazy.39008.9
Antiy-AVLTrojan[Dropper]/Win32.Agent
MicrosoftPWS:Win32/OnLineGames.LP
XcitiumTrojWare.Win32.PSW.Onlinegames.OQU.1@1qh26r
ArcabitTrojan.Doina.D494A
ZoneAlarmTrojan-Dropper.Win32.Agent.hhwa
GDataGen:Variant.Doina.18762
GoogleDetected
AhnLab-V3Trojan/Win32.OnlineGameHack.R39468
McAfeeGenericRXEK-DZ!A1942EA67295
MAXmalware (ai score=80)
VBA32Heur.Trojan.Hlux
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_ONLINEG.NUR
RisingStealer.Zuten!1.64CA (CLASSIC)
YandexTrojan.GenAsa!3e66IijIDAQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Onlinegames.QNW!tr
BitDefenderThetaAI:Packer.C2CB61B220
AVGWin32:GenMalicious-HAE [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove PWS:Win32/OnLineGames.LP?

PWS:Win32/OnLineGames.LP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment