Malware

PWS:Win32/OnLineGames!pz removal guide

Malware Removal

The PWS:Win32/OnLineGames!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/OnLineGames!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine PWS:Win32/OnLineGames!pz?


File Info:

name: 1C32A02D4F39CEE99F52.mlw
path: /opt/CAPEv2/storage/binaries/b1826bac86b062ce5cbeaf02c9c1093178b962792e782391f5649f63e1e01e9f
crc32: 865A3815
md5: 1c32a02d4f39cee99f5255eb4cf9e1de
sha1: 17fbef6829df2ba9b7cf5048b0142d2e69c5bc76
sha256: b1826bac86b062ce5cbeaf02c9c1093178b962792e782391f5649f63e1e01e9f
sha512: 26e575de7ca2930c5d56053d4a1c187928a6fa6c696eec84de332b2bed3b819e0c0e91cf5902c249cca1ffa3949ff9f287169a5c78f5eb980a942c3e298f01b3
ssdeep: 1536:1zExMwCGQ2jn0TyYRnNjs6eUoehsjLnMp3LPn:1I+wCGvrtmBfoQYMFn
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1FD43C0E59A3569BAFB5F89378FFF782C8B0423B6FA135597542A65900437352AF0300E
sha3_384: ee58828df4538851e23960bddef65b5a8fd4664eed000769a393df268771bbc700dd2c15a28d754390483e64e654a421
ep_bytes: 807c2408010f85b901000060be009000
timestamp: 2011-04-06 18:16:35

Version Info:

0: [No Data]

PWS:Win32/OnLineGames!pz also known as:

BkavW32.FamVT.Kykymber.P.Trojan
LionicTrojan.Win32.Generic.luew
AVGWin32:Trojan-gen
MicroWorld-eScanTrojan.PWS.Onlinegames.KEGA
FireEyeGeneric.mg.1c32a02d4f39cee9
CAT-QuickHealTrojan.OnLineGames.gen
SkyhighBehavesLike.Win32.PWSOnlineGames.qm
McAfeePWS-OnlineGames.ke
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kykymber.Win32.2027
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0037c4831 )
AlibabaTrojanPSW:Win32/Kykymber.d00e4af1
K7GWTrojan ( 0037c4831 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.753C057A20
SymantecInfostealer.Gampass
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/PSW.Kykymber.AA
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Agent-365464
BitDefenderTrojan.PWS.Onlinegames.KEGA
NANO-AntivirusTrojan.Win32.OnLineGames.bkxdd
AvastWin32:Trojan-gen
TencentTrojan.PSW.Win32.MiBao.a
EmsisoftTrojan.PWS.Onlinegames.KEGA (B)
BaiduWin32.Trojan-PSW.OLGames.b
F-SecureTrojan.TR/Spy.Gen
DrWebTrojan.PWS.Qq.5
VIPRETrojan.PWS.Onlinegames.KEGA
TrendMicroTSPY_KYMBER.SMDV
Trapminemalicious.moderate.ml.score
SophosMal/PWS-GZ
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.efii
WebrootW32.Trojan.Pws.Kykymber
VaristW32/OnlineGames.FL.gen!Eldorado
AviraTR/Spy.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[PSW]/Win32.Kykymber
KingsoftWin32.PSWTroj.Undef.a
MicrosoftPWS:Win32/OnLineGames!pz
XcitiumTrojWare.Win32.PSW.GamePass.F@35ift2
ArcabitTrojan.PWS.Onlinegames.KEGA
ViRobotTrojan.Win32.A.PSW-Kykymber.63664.A[UPX]
ZoneAlarmTrojan-PSW.Win32.Kykymber.dnca
GDataWin32.Trojan-Spy.OnlineGames.N
GoogleDetected
AhnLab-V3Win-Trojan/OnlineGameHack45.Gen
VBA32BScope.TrojanPSW.QQPass
ALYacTrojan.PWS.Onlinegames.KEGA
TACHYONTrojan-PWS/W32.Kykymber.70464.B
Cylanceunsafe
PandaTrj/Kykymber.A
TrendMicro-HouseCallTSPY_KYMBER.SMDV
RisingTrojan.PSW.Win32.OnlineGame.bdi (CLASSIC)
YandexTrojan.GenAsa!zT5/8dn9vmo
IkarusTrojan-PWS.Win32.OnLineGames
MaxSecurenot-a-virus-PSW-OnlineGames.Gen
FortinetW32/Onlinegames.XQB!tr
DeepInstinctMALICIOUS

How to remove PWS:Win32/OnLineGames!pz?

PWS:Win32/OnLineGames!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment