Worm

Worm:Win32/Picsys!pz removal guide

Malware Removal

The Worm:Win32/Picsys!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Picsys!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Worm:Win32/Picsys!pz?


File Info:

name: 74EACE84FA2B3F39BE55.mlw
path: /opt/CAPEv2/storage/binaries/01f6cf86bf1dd5364d01246602cf796bc43804e0082f918f16806cc9a495dadc
crc32: 677E5D46
md5: 74eace84fa2b3f39be55f0b65607e802
sha1: 98c13bd92ae188d39bceb510f71dd6bbcf141bf1
sha256: 01f6cf86bf1dd5364d01246602cf796bc43804e0082f918f16806cc9a495dadc
sha512: 440484ce08585fba232aa9d20a500fb004f27bd54b39675cb94a9719fb3a2788fc24ff6fc7731bf8a0749adf64fed9230f14770f710b9938f6ef0206e3a96c70
ssdeep: 6144:BcaJuB4qMyfnp7xPxCWk28i/RTxYT52MZM1d:f6rMOnpNPQ1K/gM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10694E003F9E0C432D09146FC1D26D7B4BA3B75B12EA4855BF39D8B0E6E74680AC5E25B
sha3_384: 161977acca9b871ecfb9f3afa774e6d8d5276fb2192838864b26c2c4671a496892f8fa1c49600648f3fff10b8211dd36
ep_bytes: 487d4444c87325cff930f918b40bee0f
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Picsys!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Fragtor.267334
SkyhighBehavesLike.Win32.Generic.gt
McAfeeGenericRXAA-FA!74EACE84FA2B
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.92ae18
ArcabitTrojan.Fragtor.D41446
BaiduWin32.Worm.Picsys.a
SymantecW32.HLLW.Yoof
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Picsys-9630818-0
BitDefenderGen:Variant.Fragtor.267334
AvastWin32:Picsys-B [Wrm]
SophosGeneric ML PUA (PUA)
F-SecureWorm.WORM/Picsys.aiqbc
DrWebWin32.HLLW.Morpheus.3
VIPREGen:Variant.Fragtor.267334
TrendMicroTROJ_GEN.R03BC0DAA24
EmsisoftGen:Variant.Fragtor.267334 (B)
IkarusP2P-Worm.Win32.Picsys.b
VaristW32/Picsys.C.gen!Eldorado
AviraWORM/Picsys.aiqbc
Antiy-AVLWorm[P2P]/Win32.Cosmu.a
Kingsoftmalware.kb.b.995
MicrosoftWorm:Win32/Picsys!pz
GDataWin32.Worm.Picsys.B
GoogleDetected
AhnLab-V3Worm/Win.Picsys.R566934
BitDefenderThetaGen:NN.ZexaCO.36680.zmZ@aiv69@i
ALYacGen:Variant.Fragtor.267334
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DAA24
RisingWorm.Picsys!1.C132 (CLASSIC)
YandexBackDoor.Siex!/Xv1UyKC8k4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Generic.AC.2C8E!tr
AVGWin32:Picsys-B [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Worm:Win32/Picsys!pz?

Worm:Win32/Picsys!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment