Malware

PWS:Win32/OnLineGames.IZ (file analysis)

Malware Removal

The PWS:Win32/OnLineGames.IZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/OnLineGames.IZ virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine PWS:Win32/OnLineGames.IZ?


File Info:

name: F2D5AA2178790AD4D716.mlw
path: /opt/CAPEv2/storage/binaries/d96cd538138a561781cb8eab429a6b573f6bdf358a2d2b8c984e573aad09794b
crc32: 1EC997DD
md5: f2d5aa2178790ad4d7160e7cfeefca9c
sha1: cf8a6c3a07b8debf7723eb3faec075a9efc7e3f1
sha256: d96cd538138a561781cb8eab429a6b573f6bdf358a2d2b8c984e573aad09794b
sha512: 02413b291dcfab7e50257ad42f443561ff2d8ad4bd579cc99454752b4b39583bc20f7b3bb62ac25d2bbc7eb146cb6cae7a51bc82d37b8429e9ad3efcc83fb480
ssdeep: 1536:jt+xVKz+tjjibQRmNWYjA0tByUo5t51NVMWPi+BA7MQxbktme9:jCwz+tnHYZ0p5hMWKL7MQxbkQe9
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T10E93AF5C9500687BD37B4936A85A3B378A3911B22D47A04B9732F09D3DB7190EF0AF4B
sha3_384: 150e891a4e9b8aeaadac840e854601551c438df28cfb672754b5751495b21202223fd77acff42134e83501fe4a87cc2d
ep_bytes: 558bec81ec1c0100008b450c53485685
timestamp: 2010-10-17 12:31:42

Version Info:

0: [No Data]

PWS:Win32/OnLineGames.IZ also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Kykymber.lxga
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Gamania.29819
MicroWorld-eScanTrojan.PWS.Onlinegames.KEGA
FireEyeGeneric.mg.f2d5aa2178790ad4
SkyhighBehavesLike.Win32.PWSOnlineGames.nt
McAfeeGenDownloader.rw
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kykymber.Win32.1433
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/Kykymber.989e1df2
K7GWRiskware ( 000027db1 )
K7AntiVirusRiskware ( 000027db1 )
BitDefenderThetaGen:NN.ZedlaF.36802.fm7@ay37yJg
VirITTrojan.Win32.Generic.AEJF
SymantecInfostealer.Gampass
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/PSW.Kykymber.AA
APEXMalicious
TrendMicro-HouseCallTSPY_KYMBER.SMDZ
ClamAVWin.Spyware.78845-2
KasperskyTrojan-PSW.Win32.Kykymber.jzk
BitDefenderTrojan.PWS.Onlinegames.KEGA
NANO-AntivirusTrojan.Win32.OnLineGames.bkxdd
AvastWin32:Kykymber [Trj]
EmsisoftTrojan.PWS.Onlinegames.KEGA (B)
GoogleDetected
F-SecureDropper.DR/PSW.Kykymber.JZ
BaiduWin32.Trojan-PSW.OLGames.ay
VIPRETrojan.PWS.Onlinegames.KEGA
TrendMicroTSPY_KYMBER.SMDZ
Trapminemalicious.high.ml.score
SophosMal/PWS-AL
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PSW.Kykymber.pn
WebrootW32.Malware.gen
VaristW32/Kykymber.A.gen!Eldorado
AviraDR/PSW.Kykymber.JZ
MAXmalware (ai score=100)
Antiy-AVLTrojan[PSW]/Win32.Kykymber.aa
KingsoftWin32.PSWTroj.Undef.a
MicrosoftPWS:Win32/OnLineGames.IZ
XcitiumTrojWare.Win32.PSW.GamePass.A@2mkvni
ArcabitTrojan.PWS.Onlinegames.KEGA
ZoneAlarmTrojan-PSW.Win32.Kykymber.jzk
GDataWin32.Trojan.PSE.13LF282
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Onlinegamehack48.Gen
Acronissuspicious
VBA32BScope.TrojanPSW
ALYacTrojan.PWS.Onlinegames.KEGA
Cylanceunsafe
PandaTrj/Kykymber.A
RisingTrojan.PSW.Win32.GameOnlineX.hp (CLASSIC)
YandexTrojan.PWS.Kykymber!Va5GkYTjz7M
IkarusTrojan-PWS.Win32.Kykymber
MaxSecurenot-a-virus-PSW-OnlineGames.Gen
FortinetW32/OnLineGames.KY!tr.pws
AVGWin32:Kykymber [Trj]
DeepInstinctMALICIOUS

How to remove PWS:Win32/OnLineGames.IZ?

PWS:Win32/OnLineGames.IZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment