Malware

PWS:Win32/OnLineGames.LW removal guide

Malware Removal

The PWS:Win32/OnLineGames.LW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/OnLineGames.LW virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine PWS:Win32/OnLineGames.LW?


File Info:

name: D6470240563C8004D45B.mlw
path: /opt/CAPEv2/storage/binaries/432c8debafab46fe9b8f89a1714505adde27b4a1a658178b6b5564bc152c3246
crc32: E518FF8F
md5: d6470240563c8004d45b0f8bfccca669
sha1: 37c2d95ae9ef6ba5dc6da2da9513251419aec529
sha256: 432c8debafab46fe9b8f89a1714505adde27b4a1a658178b6b5564bc152c3246
sha512: 3a38e1de77329a8ec04e418802c317d0daeef596df66623776842e49e50b4cf381010628c728340631ccd1746053d83dc5740ec54b11b661157a187fbe1b5189
ssdeep: 1536:i6t9nGaYzrmdiWfUGnc/Ye4Hm1IjTMMlU3JoApT1d6J:i6r+6BUx//8AkT5lU3JoaxA
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T13463AF59861526B6C37F8A36989B392B8D3926737D47608BC72210CA3C771C2EF15F0B
sha3_384: b87589825dcfe73879148e66cb36ae72eaf09bf62a81ae46f8808049558839513559bb2694f36d4a92c5e8628f3d2453
ep_bytes: 558bec81ec040100008b450c56485785
timestamp: 2011-03-21 18:41:30

Version Info:

0: [No Data]

PWS:Win32/OnLineGames.LW also known as:

BkavW32.FamVT.KyberNHc.Trojan
LionicTrojan.Win32.Kykymber.lopc
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.PWS.Onlinegames.KEGA
CAT-QuickHealTrojan.OnLineGames.gen
SkyhighBehavesLike.Win32.PWSOnlineGames.km
McAfeePWS-OnlineGames.ke
Cylanceunsafe
ZillyaTrojan.Kykymber.Win32.3992
SangforSuspicious.Win32.Save.ins
K7AntiVirusPassword-Stealer ( 0018a90c1 )
AlibabaTrojanPSW:Win32/Kykymber.2c9fc00b
K7GWPassword-Stealer ( 0018a90c1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZedlaF.36680.eu7@aq4Cmed
SymantecInfostealer.Gampass
ESET-NOD32a variant of Win32/PSW.Kykymber.AA
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Spyware.78845-2
KasperskyTrojan-PSW.Win32.Kykymber.dncd
BitDefenderTrojan.PWS.Onlinegames.KEGA
NANO-AntivirusTrojan.Win32.OnLineGames.bkxdd
AvastWin32:OnLineGames-FXK [Trj]
TencentTrojan.Win32.Sott.thc
EmsisoftTrojan.PWS.Onlinegames.KEGA (B)
BaiduWin32.Trojan-PSW.Kykymber.a
F-SecureDropper.DR/PSW.Kykymber.JZ
DrWebTrojan.PWS.Qq.5
VIPRETrojan.PWS.Onlinegames.KEGA
TrendMicroTROJ_GEN.R002C0DK323
SophosMal/PWS-GZ
IkarusTrojan-PWS.Win32.Kykymber
GDataWin32.Trojan-Spy.OnlineGames.N
JiangminTrojan/Generic.dzun
WebrootW32.InfoStealer.OnlineGames.Gen
VaristW32/OnlineGames.FL.gen!Eldorado
AviraDR/PSW.Kykymber.JZ
Antiy-AVLTrojan[PSW]/Win32.Kykymber.aa
KingsoftWin32.HeurC.KVMH008.a
XcitiumTrojWare.Win32.PSW.Kykymber.mbj@4b49ku
ArcabitTrojan.PWS.Onlinegames.KEGA
ViRobotTrojan.Win32.A.PSW-Kykymber.46104
ZoneAlarmTrojan-PSW.Win32.Kykymber.dncd
MicrosoftPWS:Win32/OnLineGames.LW
GoogleDetected
AhnLab-V3Trojan/Win32.OnlineGameHack.R1787
VBA32BScope.TrojanPSW.Kykymber
TACHYONTrojan-PWS/W32.Kykymber.68856
MalwarebytesMalware.AI.3978757283
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DK323
RisingStealer.QQPass!1.659F (CLASSIC)
YandexTrojan.PWS.Kykymber!l7q+pHAIuNU
SentinelOneStatic AI – Malicious PE
MaxSecurenot-a-virus-PSW-OnlineGames.Gen
FortinetW32/Onlinegames.XQB!tr
AVGWin32:OnLineGames-FXK [Trj]
DeepInstinctMALICIOUS

How to remove PWS:Win32/OnLineGames.LW?

PWS:Win32/OnLineGames.LW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment