Win32 PSW.OnLineGames is a very smart virus that uses shared memory access to infect a computer system. Along with the symptoms mentioned above, it does make some changes in the system registry and also adds certain files to the windows directory, system directory and program files directory.
To detect the presence of this virus on your computer, you can check the User_Name/Local Settings/Temp folder. Here, you can find an executable file that has a combination of numbers and alphabets in its name.
It also adds iknbnmcc.dll to the system directory of the windows folder, i.e. windows/system32. Another symptom is a change in system registry where an existing entry’s value is replaced with a new value.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\currentversion\shellserviceobjectdelayload\247b76cc = {247b76cc-4c60-4d57-bc43-9fad5f7214ff}
Along with a change in the registry, it adds a new entry to register the iknbnmcc.dll file copied to the windows/system32 folder.