Malware

Heur.PWSIME.3 (B) (file analysis)

Malware Removal

The Heur.PWSIME.3 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.PWSIME.3 (B) virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify proxy settings
  • Attempts to create or modify system certificates

Related domains:

ip.chinaz.com
www.ipip.net
en.ipip.net
www.yz.x5xg.com

How to determine Heur.PWSIME.3 (B)?


File Info:

crc32: DC57CD9F
md5: fb64a27dff69743e1dc2413d6ba33332
name: ____________7.2___.exe
sha1: 56df1684ea726062588c9890c19aeaaec69ea234
sha256: ae0f70ac53f4eb11fa6b57bb80d6c9bdb69b7992bd0ab2eb9d5fb59b7da03808
sha512: 30351d3b2dacca16fb74ae058dff3014f099c8f8fa4b6288f3189a6474fa7d7b43f74e8413d6a470970346be6f9c48ff007ea16027ce7bad327bb79aff9c4c76
ssdeep: 49152:6fhAhKjZk4Ubx+UFrzbMX3fLRzSPulOyy36WiJIL666V0O2egD31ms:whYMX31zSPullyqLJIJs0Gi3j
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: www.x5xg.com
FileVersion: 2.9.0.0
CompanyName: x70abx821ex661fx5149x52a9x624b
Comments: x70abx821ex661fx5149x52a9x624b www.x5xg.com
ProductName: x70abx821ex661fx5149x7effx8272x533ax52a9x624b
ProductVersion: 2.9.0.0
FileDescription: x70abx821ex661fx5149x52a9x624b www.x5xg.com
Translation: 0x0804 0x04b0

Heur.PWSIME.3 (B) also known as:

BkavW32.AIDetectVM.malware
DrWebTool.Siggen.8366
MicroWorld-eScanGen:Heur.PWSIME.3
FireEyeGeneric.mg.fb64a27dff69743e
CAT-QuickHealTrojan.Generic.2919
McAfeeGenericRXAA-AA!FB64A27DFF69
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005246d51 )
BitDefenderGen:Heur.PWSIME.3
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.dff697
BitDefenderThetaGen:NN.ZexaF.34082.@t0@aS!Xehbb
CyrenW32/OnlineGames.HH.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Malware.Onlinegames-6629257-0
GDataWin32.Application.FlyStudio.F
Kasperskynot-a-virus:RiskTool.Win32.IMEStartup.ah
AlibabaRiskWare:Win32/IMEStartup.ce04f415
RisingTrojan.Occamy!8.F1CD (RDMK:cmRtazrn3Rn/ONwBsNSUx11RB7cK)
Ad-AwareGen:Heur.PWSIME.3
SophosGeneric PUA FG (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.rh
EmsisoftGen:Heur.PWSIME.3 (B)
SentinelOneDFI – Malicious PE
F-ProtW32/OnlineGames.HH.gen!Eldorado
JiangminTrojan/PSW.Magania.bfhe
Antiy-AVLGrayWare/Win32.FlyStudio.a
Endgamemalicious (high confidence)
ArcabitTrojan.PWSIME.3
ZoneAlarmnot-a-virus:RiskTool.Win32.IMEStartup.ah
MicrosoftTrojan:Win32/Wacatac.D!ml
AhnLab-V3Malware/Win32.Generic.C2713419
Acronissuspicious
VBA32BScope.Downloader.Snojan
ALYacGen:Heur.PWSIME.3
MAXmalware (ai score=85)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R01FH0CAF20
TencentWin32.Trojan.Imeinject.Eequ
IkarusPUA.BlackMoon
eGambitHackTool.Generic
FortinetW32/Agent.65CA!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Heur.PWSIME.3 (B)?

Heur.PWSIME.3 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment