Malware

What is “PWS:Win32/OnLineGames.IZ”?

Malware Removal

The PWS:Win32/OnLineGames.IZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/OnLineGames.IZ virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine PWS:Win32/OnLineGames.IZ?


File Info:

name: D24D30CE6A237F7ABB45.mlw
path: /opt/CAPEv2/storage/binaries/5f0cad1f1e7ba870cecbb21b8d746005d801ba8640e81f6224a7e9f15e131e21
crc32: EB55BAAE
md5: d24d30ce6a237f7abb452974d68a460e
sha1: 1d3ad68be14ecb77ada65c14a203d6c7d3b35d00
sha256: 5f0cad1f1e7ba870cecbb21b8d746005d801ba8640e81f6224a7e9f15e131e21
sha512: 4255131be68fb36a11166a7cbe81b7a6f23b2f969111993e3e299c1499065efc01f441262c4290b74d4f0e48b5bb01f6d650d90ea5d240664f98dd5d69d06b62
ssdeep: 1536:pn12GQV2E4XdYwTt2HCLVrBcmvrhWAkDRV/9z7rpvOfY:x12t2EOdXVVP1Wd3p5cY
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1F4A3A0999515B637D37FC936684E39364A2D26B27E43949BC732E14434B30F1AB0AE0B
sha3_384: 9f7b3c7eda2296a65ddc86812437ffa1ccc8252ee6d523de7002865fe996471710a3025dcd6c78ac652ee91a195b1883
ep_bytes: 558bec81ec1c0100008b450c53485685
timestamp: 2010-10-15 13:09:33

Version Info:

0: [No Data]

PWS:Win32/OnLineGames.IZ also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Kykymber.lxga
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.PWS.Onlinegames.KEGA
FireEyeGeneric.mg.d24d30ce6a237f7a
CAT-QuickHealTrojan.OnlinegaPMF.S27496846
SkyhighBehavesLike.Win32.PWSOnlineGames.ct
McAfeeGenDownloader.rw
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kykymber.Win32.1415
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/Kykymber.175af8ce
K7GWRiskware ( 000027db1 )
K7AntiVirusRiskware ( 000027db1 )
BaiduWin32.Trojan-PSW.OLGames.ay
VirITTrojan.Win32.Agent2.AFKB
SymantecInfostealer.Gampass
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/PSW.Kykymber.AA
APEXMalicious
TrendMicro-HouseCallMal_OLGM-35
ClamAVWin.Spyware.78845-2
KasperskyTrojan-PSW.Win32.Kykymber.jzj
BitDefenderTrojan.PWS.Onlinegames.KEGA
NANO-AntivirusTrojan.Win32.OnLineGames.bkxdd
AvastWin32:Kykymber [Trj]
TencentTrojan.Win32.OnlineGame.i
EmsisoftTrojan.PWS.Onlinegames.KEGA (B)
GoogleDetected
F-SecureDropper.DR/PSW.Kykymber.JZ.1
DrWebTrojan.PWS.Gamania.29820
VIPRETrojan.PWS.Onlinegames.KEGA
TrendMicroMal_OLGM-35
Trapminemalicious.high.ml.score
SophosMal/PWS-AL
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.N540AG
JiangminTrojan/PSW.Kykymber.qn
WebrootW32.Trojan.Kykymber.Gen
VaristW32/Kykymber.A.gen!Eldorado
AviraDR/PSW.Kykymber.JZ.1
MAXmalware (ai score=100)
Antiy-AVLTrojan[PSW]/Win32.Kykymber.aa
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.PSW.GamePass.A@2mkvni
ArcabitTrojan.PWS.Onlinegames.KEGA
ZoneAlarmTrojan-PSW.Win32.Kykymber.jzj
MicrosoftPWS:Win32/OnLineGames.IZ
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Onlinegamehack48.Gen
Acronissuspicious
VBA32BScope.TrojanPSW
ALYacTrojan.PWS.Onlinegames.KEGA
Cylanceunsafe
PandaTrj/Kykymber.A
RisingTrojan.PSW.Win32.OnlineGame.ayn (CLASSIC)
IkarusTrojan-PWS.Win32.Kykymber
MaxSecurenot-a-virus-PSW-OnlineGames.Gen
FortinetW32/Onlinegames.XQB!tr
BitDefenderThetaAI:Packer.02D3340520
AVGWin32:Kykymber [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan

How to remove PWS:Win32/OnLineGames.IZ?

PWS:Win32/OnLineGames.IZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment