Malware

About “Win32/PSW.OnLineGames.OQU” infection

Malware Removal

The Win32/PSW.OnLineGames.OQU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSW.OnLineGames.OQU virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/PSW.OnLineGames.OQU?


File Info:

name: D5F02805512CF9D191E9.mlw
path: /opt/CAPEv2/storage/binaries/bdc4ebb48807c33ca81ecbd419bdd9fa2d6b0618c82a6716f9b9cffc0768de7e
crc32: 0064C955
md5: d5f02805512cf9d191e952559e3a0ba3
sha1: 0a075e185343fce26539d9d5d48f6e09458ec8f0
sha256: bdc4ebb48807c33ca81ecbd419bdd9fa2d6b0618c82a6716f9b9cffc0768de7e
sha512: 5f619e8cda11ae1b0f322335d6fafbb4bef28f52a5454c900e70f717ac5bea64d909e3e568c2c166a822cae628b3086d375676b0363aa76a963ec27c6c7c651b
ssdeep: 384:8WcHM1sl9LBLpWPdljNl2MAXNPRq3iPdGkLqOF57uu6PK/u1jz0KNuOzsR5q:2HM1e91LpWFNNlIXNpq3WbF9uu0K2dCJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16AB2D00ABE344D37D9BB21BFB2A77E1862DD162A03740342E4DC9A3B50B769C4D45267
sha3_384: 03ad6d4547f8faff89aad89b084f9204b56fe4ac38b6132e89653e267fc0e4dfbaf2437be1f67239bceb182ffad1b06d
ep_bytes: 83f8027505000000c390608d2c088b45
timestamp: 2009-12-28 15:29:01

Version Info:

0: [No Data]

Win32/PSW.OnLineGames.OQU also known as:

LionicTrojan.Win32.Generic.4!c
DrWebTrojan.MulDrop.56293
MicroWorld-eScanGen:Trojan.Heur.RP.bmX@bWsitD
FireEyeGeneric.mg.d5f02805512cf9d1
McAfeeGenericRXAA-FA!D5F02805512C
CylanceUnsafe
ZillyaTrojan.OnLineGames.Win32.42576
SangforTrojan.Win32.ULPM.Gen
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.5512cf
BitDefenderThetaAI:Packer.C2A4EDFD1D
VirITTrojan.Win32.OLG.YLW
CyrenW32/OnlineGames.CW.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/PSW.OnLineGames.OQU
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Spyware.68962-2
KasperskyTrojan-GameThief.Win32.OnLineGames.bnbo
BitDefenderGen:Trojan.Heur.RP.bmX@bWsitD
NANO-AntivirusTrojan.Win32.OnLineGames.byare
AvastFileRepMalware [Trj]
TencentWin32.Trojan-gamethief.Onlinegames.Wtwy
Ad-AwareGen:Trojan.Heur.RP.bmX@bWsitD
TACHYONTrojan-PWS/W32.WebGame.24213.B
EmsisoftGen:Trojan.Heur.RP.bmX@bWsitD (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
VIPREGen:Trojan.Heur.RP.bmX@bWsitD
McAfee-GW-EditionBehavesLike.Win32.Trojan.mc
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/HckPk-A
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Heur.RP.bmX@bWsitD
JiangminTrojan/AntiHeur.bt
GoogleDetected
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.12
KingsoftWin32.Heur.KVMH004.a.(kcloud)
ArcabitTrojan.Heur.RP.ED730A
ZoneAlarmTrojan-GameThief.Win32.OnLineGames.bnbo
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.OnlineGameHack.R20878
Acronissuspicious
ALYacGen:Trojan.Heur.RP.bmX@bWsitD
MAXmalware (ai score=85)
MalwarebytesMalware.Heuristic.1003
RisingStealer.GameOL!1.6670 (CLOUD)
YandexTrojan.GenAsa!6yPhg6YTIyM
IkarusTrojan.Win32.VB
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Onlinegames.JBRVSTD!tr.pws
AVGFileRepMalware [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/PSW.OnLineGames.OQU?

Win32/PSW.OnLineGames.OQU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment