Trojan

About “TrojanDropper:AutoIt/Pistolar!pz” infection

Malware Removal

The TrojanDropper:AutoIt/Pistolar!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:AutoIt/Pistolar!pz virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine TrojanDropper:AutoIt/Pistolar!pz?


File Info:

name: 6828FA2CEF4376247E16.mlw
path: /opt/CAPEv2/storage/binaries/4b644a521b09481ba2606390ddbde69cfea3a394a7d3e8bf7bb2bca4dc434082
crc32: 7E80FEBE
md5: 6828fa2cef4376247e16b5c5f9ecae54
sha1: 60c227e96312258c84bf2f8cfbfafb6001ace3de
sha256: 4b644a521b09481ba2606390ddbde69cfea3a394a7d3e8bf7bb2bca4dc434082
sha512: a69a18b2222f14ce359ee1b2b34b7a24532c1b7e26053e59e9b1778819a0b2765772f06d140eea6a96223d066cdef4264dc52f909a66d776a8481e9eae0ee38e
ssdeep: 12288:9hkDgouVA2nxKkorvdRgQriDwOIxmxiZnYQE7PJcbNyS6Wq4aaE6KwyF5L1:LRmJkcoQricOIQxiZY12NyQthEl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C7F4B021B5D69036C2B323B19E7EF36A9A3D79360336D29727C82D315EA05416B39733
sha3_384: 9ee25e8532c79cb061305180576611c2b6f2ba196b881601aed5846e328d85c615ffa08e7d2f44f6443a0cc21cae72f9
ep_bytes: e816900000e989feffffcccccccccc55
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

TrojanDropper:AutoIt/Pistolar!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.8121236
CAT-QuickHealTrojan.AutoIt.Pistolar.A
SkyhighAutoit.Dropper.gen.a
McAfeeAutoit.Dropper.gen.a
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.AutoitGen.Win32.946
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000111 )
K7GWTrojan ( 700000111 )
Cybereasonmalicious.963122
ArcabitTrojan.Generic.D7BEB94
BitDefenderThetaAI:Packer.05DA809615
SymantecW32.SillyFDC
ESET-NOD32multiple detections
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Autoit-6981134-0
KasperskyTrojan.Win32.Autoit.blz
BitDefenderTrojan.Generic.8121236
NANO-AntivirusTrojan.Script.AutoIt.dbycns
AvastAutoIt:Agent-DP [Trj]
EmsisoftTrojan.Generic.8121236 (B)
BaiduAutoIt.Worm.Agent.a
F-SecureTrojan.TR/Dropper.Gen
DrWebBackDoor.IRC.Bot.3238
VIPRETrojan.Generic.8121236
SophosW32/AutoIt-QA
IkarusWorm.Win32.AutoIt
JiangminTrojan.Generic.ixgl
VaristW32/AutoIt.WG.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Autoit
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDropper:AutoIt/Pistolar!pz
ZoneAlarmHEUR:Trojan.Win32.Hesv.gen
GDataTrojan.Generic.8121236
GoogleDetected
AhnLab-V3Trojan/Win32.AutoIt.R258728
VBA32Trojan.Autoit
Cylanceunsafe
PandaTrj/Autoit.gen
RisingDropper.Pistolar/Autoit!1.A603 (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Autoit.AZA
FortinetW32/Autoit.HZ!worm
AVGAutoIt:Agent-DP [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDropper:AutoIt/Pistolar!pz?

TrojanDropper:AutoIt/Pistolar!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment