Malware

PWS:Win32/Kotwir.C removal tips

Malware Removal

The PWS:Win32/Kotwir.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Kotwir.C virus can do?

  • Executable code extraction
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine PWS:Win32/Kotwir.C?


File Info:

crc32: 0423E4E1
md5: e6d0c6c7d907268b4abe5ec52dd6a455
name: E6D0C6C7D907268B4ABE5EC52DD6A455.mlw
sha1: c1f512340a0b2f219a8797d2ccc09e64a99774a6
sha256: 2480c6939da6d13538f88736dbdaa55bf7c1db1589a7b9149769432d5a599fa4
sha512: 6691934146413a443e73fb6304bad727753c472ddcf5319131a9851464324dd8781e9b1947b1567b5b69045e2d2e06c82cf661d01e46a6614b481268b8d93120
ssdeep: 1536:ZzBnb2PIHYIwstA2ZlxBMDbqB1Iz7tulBSTiWDZBe/bffXezzj341OD2:ZNnb2PfIwstA2Zn0uQG4lDZBe7fCez
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PWS:Win32/Kotwir.C also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0054b3a81 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Wsgame.6930
CynetMalicious (score: 100)
CMCGeneric.Win32.e6d0c6c7d9!CMCRadar
ALYacTrojan.Dropper.OnlineGames
CylanceUnsafe
ZillyaTrojan.OnLineGames.Win32.75503
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanPSW:Win32/Kotwir.64a8fe9a
K7GWTrojan ( 0054b3a81 )
Cybereasonmalicious.7d9072
CyrenW32/Zbot.W.gen!Eldorado
SymantecTrojan.Packed.NsAnti
ESET-NOD32a variant of Win32/Pacex.Gen
APEXMalicious
AvastWin32:Oliga [Trj]
ClamAVWin.Spyware.44667-2
KasperskyPacked.Win32.Krap.b
BitDefenderPacker.Malware.NSAnti.1
NANO-AntivirusTrojan.Win32.NSAnti.fthc
ViRobotTrojan.Win32.PSWLineage.91986
MicroWorld-eScanPacker.Malware.NSAnti.1
TencentWin32.Virus.Pacex.Amls
Ad-AwarePacker.Malware.NSAnti.1
SophosMal/Generic-S
ComodoTrojWare.Win32.PSW.Gamania.GenA@1oom6i
BitDefenderThetaAI:Packer.0C62F9921D
VIPREPacked.Win32.Krap.b (v)
TrendMicroMal_Nsanti-5
McAfee-GW-EditionBehavesLike.Win32.Generic.mc
FireEyeGeneric.mg.e6d0c6c7d907268b
EmsisoftPacker.Malware.NSAnti.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminPacked.Krap.Gen.a
WebrootW32.Trojan.Phisher-Lineage
AviraTR/ATRAPS.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.96412E
KingsoftWin32.Hack.NSAnti.ge.(kcloud)
MicrosoftPWS:Win32/Kotwir.C
ArcabitPacker.Malware.NSAnti.1
GDataPacker.Malware.NSAnti.1
TACHYONTrojan-PWS/W32.WebGame.91986
Acronissuspicious
McAfeePWS-Gamania.gen.a
MAXmalware (ai score=100)
VBA32Malware-Cryptor.Win32.NSAnti
PandaW32/Gamania.gen
TrendMicro-HouseCallMal_Nsanti-5
RisingVirus.Mian007!1.9ADC (CLASSIC)
YandexTrojan.Lineage.Gen!Pac.3
IkarusTrojan-GameThief.Win32.Magania
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Packed.ONLINEGAMES.gen!tr
AVGWin32:Oliga [Trj]
Paloaltogeneric.ml

How to remove PWS:Win32/Kotwir.C?

PWS:Win32/Kotwir.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment