Worm

Worm:Win32/Picsys!pz malicious file

Malware Removal

The Worm:Win32/Picsys!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Picsys!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Worm:Win32/Picsys!pz?


File Info:

name: 85EDC2C4A4CDF900A1CE.mlw
path: /opt/CAPEv2/storage/binaries/0586f601741a3ca5432ee1866537432ed59a71014e004a9fb656453dd2e08e25
crc32: 233BE8F1
md5: 85edc2c4a4cdf900a1ceb8bf7d66377d
sha1: b4690aae2318926bcdd85e5127387fa4f85df8e1
sha256: 0586f601741a3ca5432ee1866537432ed59a71014e004a9fb656453dd2e08e25
sha512: 78fedf39fc2ba86d78e22fc1e1d5a7109571c83d12e8994a64e330049328a4d64c05945e63edb05ffa43e040e757cb773b6de8986dbe3ec37351f4070d96a330
ssdeep: 6144:BcaJu54qMyfnp7xPxLDsDOScJ4xYT52MZM1d:fqrMOnpNPB0OScRM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10394E103F9E1C431D0914AF81D36CBB8BA3B79B11DA4864BF39D8B0E6E74690AC5D257
sha3_384: f0f18615e597676ecf0e5142c646fd7539b24df0f00991e0a2aa81fe2681ff4e355e25b29ea9ada07266d7a5ee04d809
ep_bytes: 487d4444c87325cff930f918b40bee0f
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Picsys!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.267334
SkyhighBehavesLike.Win32.Generic.gt
McAfeeGenericRXAA-FA!85EDC2C4A4CD
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Fragtor.267334
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.e23189
BaiduWin32.Worm.Picsys.a
SymantecW32.HLLW.Yoof
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Picsys-9630818-0
BitDefenderGen:Variant.Fragtor.267334
AvastWin32:Picsys-B [Wrm]
EmsisoftGen:Variant.Fragtor.267334 (B)
F-SecureWorm.WORM/Picsys.mfjqw
DrWebWin32.HLLW.Morpheus.3
TrendMicroTROJ_GEN.R03BC0DAK24
SophosGeneric ML PUA (PUA)
IkarusP2P-Worm.Win32.Picsys.b
VaristW32/Picsys.C.gen!Eldorado
AviraWORM/Picsys.mfjqw
Antiy-AVLWorm[P2P]/Win32.Cosmu.a
Kingsoftmalware.kb.b.994
MicrosoftWorm:Win32/Picsys!pz
ArcabitTrojan.Fragtor.D41446
GDataWin32.Worm.Picsys.B
GoogleDetected
AhnLab-V3Worm/Win.Picsys.R566934
BitDefenderThetaGen:NN.ZexaCO.36680.zmZ@aiv69@i
ALYacGen:Variant.Fragtor.267334
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DAK24
RisingWorm.Picsys!1.C132 (CLASSIC)
YandexBackDoor.Siex!/Xv1UyKC8k4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Generic.AC.2C8E!tr
AVGWin32:Picsys-B [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Worm:Win32/Picsys!pz?

Worm:Win32/Picsys!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment