Malware

Win32/PSW.OnLineGames.QVB removal tips

Malware Removal

The Win32/PSW.OnLineGames.QVB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSW.OnLineGames.QVB virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/PSW.OnLineGames.QVB?


File Info:

name: 0660A6451E639BDB86D4.mlw
path: /opt/CAPEv2/storage/binaries/052c4071b8b8246f56ea9288bd5711ac42d684e9de42e4dc39d1b38500f27d9d
crc32: 83635E67
md5: 0660a6451e639bdb86d45c4551ee4364
sha1: 0a06cbb8aa797cd44183cdbe26eb5662b42f8487
sha256: 052c4071b8b8246f56ea9288bd5711ac42d684e9de42e4dc39d1b38500f27d9d
sha512: 75f6414ae5920635fd94c978eb067576dfc2e60672e2a7a20f6a145595e75069cf95f64f39b7a0663212b1216589574ab3b4d0c927b0b4e9ef5e6ca63cac1b89
ssdeep: 1536:N6kyg37FycQirhTOSOGZTTGe+p8hoGAQf2fuFuuAthy:NTr37FycQi5vnGvrh2AuX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T179739C067E8B10BEE2C604B095A548EDFBFC191774A2BE2FDF40494470F21A96E794F6
sha3_384: 3d6fb0bd5dacfbd18c1483062b093d8005ae1eb411dd4571efe16ba72dd9904c5588221e7842c803933b78bb36bdd661
ep_bytes: 558bec83e4f881ec3c0a0000535657ff
timestamp: 2015-04-10 10:36:26

Version Info:

0: [No Data]

Win32/PSW.OnLineGames.QVB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.0660a6451e639bdb
CAT-QuickHealTrojan.Skeeyah.19043
McAfeeGenericRXFW-UG!0660A6451E63
SangforTrojan.Win32.Save.a
K7AntiVirusPassword-Stealer ( 004bec731 )
K7GWPassword-Stealer ( 004bec731 )
Cybereasonmalicious.51e639
BaiduWin32.Trojan.Agent.hk
VirITTrojan.Win32.Siggen6.BZER
CyrenW32/ABRisk.CECY-4907
SymantecTrojan.Gen
ESET-NOD32a variant of Win32/PSW.OnLineGames.QVB
APEXMalicious
KasperskyTrojan-Dropper.Win32.Dinwod.vjq
SophosMal/Generic-S
DrWebTrojan.Siggen6.34597
VIPREGen:Heur.Loregun.3
TrendMicroTROJ_GEN.R03BC0PHD22
McAfee-GW-EditionBehavesLike.Win32.Klez.lh
Trapminemalicious.high.ml.score
IkarusTrojan.Win32.PSW
GDataWin32.Packed.Kryptik.BV6HAT
JiangminTrojanDropper.Dinwod.pn
GoogleDetected
Antiy-AVLTrojan/Generic.ASMalwS.B24
ZoneAlarmTrojan-Dropper.Win32.Dinwod.vjq
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win32.RL_Dinwod.R356206
ALYacGen:Heur.Loregun.3
TrendMicro-HouseCallTROJ_GEN.R03BC0PHD22
RisingTrojan.Generic@AI.100 (RDML:C14tlWzCEYH5v55r/OtkCw)
SentinelOneStatic AI – Malicious PE
FortinetW32/Onlinegames.QVB!tr
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/PSW.OnLineGames.QVB?

Win32/PSW.OnLineGames.QVB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment