Worm

Worm:Win32/Picsys!pz removal guide

Malware Removal

The Worm:Win32/Picsys!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Picsys!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Worm:Win32/Picsys!pz?


File Info:

name: D670E9017F3A27CFFC3E.mlw
path: /opt/CAPEv2/storage/binaries/6dea705e5c5c05918d5a92a936d26f140a1d81310ca8b9685569373dea3f22e0
crc32: 6D493568
md5: d670e9017f3a27cffc3e1997c4ee4f8d
sha1: b8150cdd5ed0b67637e701253cb5892e3b3f716c
sha256: 6dea705e5c5c05918d5a92a936d26f140a1d81310ca8b9685569373dea3f22e0
sha512: 72b2739a3cf2bd047617b3a4770ff573dc17ff16978dababc39bdf2189f9bf4eec61bc2650f7cee329d4ddc60a4e2fb62743656bc44a72ef780dd9b79d741be4
ssdeep: 6144:BcaJuy4qMyfnp7xPxYx16Htbx895/ExYT52MZM1d:f1rMOnpNP+x16HU9lM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CF94E103F8E1C431D0914BF90D26C7E4B93BB9B11EA8515BF7AD9F0E6E75280A85D21B
sha3_384: ffcca5517efdfbd04c0d87e5913a55544abfc47aff03e90b85f653fb5fd1a378b5a74b601889c220dd66ca590cd4cd42
ep_bytes: 487d4444c87325cff930f918b40bee0f
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Picsys!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.267334
SkyhighBehavesLike.Win32.Generic.gt
McAfeeGenericRXAA-FA!D670E9017F3A
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Fragtor.267334
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
ArcabitTrojan.Fragtor.D41446
BaiduWin32.Worm.Picsys.a
SymantecW32.HLLW.Yoof
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Picsys-9630818-0
BitDefenderGen:Variant.Fragtor.267334
AvastWin32:Picsys-B [Wrm]
SophosGeneric ML PUA (PUA)
F-SecureWorm.WORM/Picsys.ncsjw
DrWebWin32.HLLW.Morpheus.3
TrendMicroTROJ_GEN.R03BC0DAI24
EmsisoftGen:Variant.Fragtor.267334 (B)
IkarusP2P-Worm.Win32.Picsys.b
VaristW32/Picsys.C.gen!Eldorado
AviraWORM/Picsys.ncsjw
Antiy-AVLWorm[P2P]/Win32.Cosmu.a
Kingsoftmalware.kb.b.996
MicrosoftWorm:Win32/Picsys!pz
GDataWin32.Worm.Picsys.B
GoogleDetected
AhnLab-V3Worm/Win.Picsys.R566934
BitDefenderThetaGen:NN.ZexaCO.36680.zmZ@aiv69@i
ALYacGen:Variant.Fragtor.267334
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DAI24
RisingWorm.Picsys!1.C132 (CLASSIC)
YandexBackDoor.Siex!/Xv1UyKC8k4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Generic.AC.2C8E!tr
AVGWin32:Picsys-B [Wrm]
Cybereasonmalicious.d5ed0b
DeepInstinctMALICIOUS

How to remove Worm:Win32/Picsys!pz?

Worm:Win32/Picsys!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment