Malware

Should I remove “PWS:Win32/OnLineGames.IZ”?

Malware Removal

The PWS:Win32/OnLineGames.IZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/OnLineGames.IZ virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine PWS:Win32/OnLineGames.IZ?


File Info:

name: 3F20006B9C1421060D89.mlw
path: /opt/CAPEv2/storage/binaries/31ec0882a064755c5358d77d8588ffa5a654db52f5dedc9cc1d005aaa7b8acc2
crc32: 02E0CA9C
md5: 3f20006b9c1421060d8957ce1890cf08
sha1: 8b7e59a301f3e1f6f80ccbbe88981677266bfba0
sha256: 31ec0882a064755c5358d77d8588ffa5a654db52f5dedc9cc1d005aaa7b8acc2
sha512: 06eb73f3bf91eba2a18964037887894fa0498eaf6f6f72f7358822df0aa9b7b5f75a2bf9a2196a732c30c2b4a4a3ca59d43aae2a4a002bdf94f4c8dcf6f1bca4
ssdeep: 1536:Nh1fL15Vx2G5bCgsSezvQu0l1mZxvjl+29/bPjbTXqrxSMH79oww5kRe3BHDC:Nh53p5NIz4u0l1mnj19D+rxt7VREM
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T10F93BFA89B62257AE72F8533589A3B37492833737D27945B533261CA3C72152FB05F0B
sha3_384: bdbe337cde002d3758c6b954c9f05e0c4fe946d42aae8e89f4ed8c28cff80ddd64463a407d614b0bd982b6429daa5673
ep_bytes: 558bec81ec040100008b450c56485785
timestamp: 2011-03-18 12:48:28

Version Info:

0: [No Data]

PWS:Win32/OnLineGames.IZ also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Kykymber.lhMk
MicroWorld-eScanTrojan.PWS.Onlinegames.KEGA
ClamAVWin.Spyware.78845-2
FireEyeGeneric.mg.3f20006b9c142106
CAT-QuickHealTrojan.OnLineGames.gen
SkyhighBehavesLike.Win32.PWSOnlineGames.nm
McAfeePWS-OnlineGames.ke
MalwarebytesMalware.AI.4174236165
VIPRETrojan.PWS.Onlinegames.KEGA
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojanPSW:Win32/OnLineGames.7d943e09
K7GWTrojan ( 0056e0a61 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan-PSW.OLGames.j
SymantecInfostealer.Gampass
ESET-NOD32a variant of Win32/PSW.OnLineGames.POT
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-GameThief.Win32.OnLineGames.xsgq
BitDefenderTrojan.PWS.Onlinegames.KEGA
NANO-AntivirusTrojan.Win32.OnLineGames.bkxdd
AvastWin32:OnLineGames-FXK [Trj]
RisingStealer.Kykymber!1.A598 (CLASSIC)
EmsisoftTrojan.PWS.Onlinegames.KEGA (B)
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebTrojan.PWS.Qq.5
ZillyaTrojan.OnLineGames.Win32.87029
TrendMicroTSPY_ONGAME.SMK
Trapminemalicious.high.ml.score
SophosMal/PWS-GZ
IkarusTrojan-PWS.Win32.Kykymber
GDataWin32.Trojan-Spy.OnlineGames.N
JiangminTrojan/PSW.Kykymber.alg
WebrootW32.Pws.Onlinegames
GoogleDetected
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan[PSW]/Win32.Kykymber.aa
Kingsoftmalware.kb.a.1000
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.PWS.Onlinegames.KEGA
ViRobotTrojan.Win32.Z.Onlinegames.96408
ZoneAlarmTrojan-GameThief.Win32.OnLineGames.xsgq
MicrosoftPWS:Win32/OnLineGames.IZ
VaristW32/OnlineGames.FL.gen!Eldorado
AhnLab-V3Trojan/Win32.OnlineGameHack.R1787
Acronissuspicious
BitDefenderThetaAI:Packer.8F032A0720
ALYacTrojan.PWS.Onlinegames.KEGA
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Kykymber
Cylanceunsafe
PandaTrj/Kykymber.A
TrendMicro-HouseCallTSPY_ONGAME.SMK
TencentTrojan.PSW.Win32.MiBao.a
YandexTrojan.PWS.OnLineGames!r+l5nQtq92I
SentinelOneStatic AI – Malicious PE
MaxSecurenot-a-virus-PSW-OnlineGames.Gen
FortinetW32/Onlinegames.XQB!tr
AVGWin32:OnLineGames-FXK [Trj]
DeepInstinctMALICIOUS

How to remove PWS:Win32/OnLineGames.IZ?

PWS:Win32/OnLineGames.IZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment