Trojan

TrojanDropper:AutoIt/Pistolar!pz malicious file

Malware Removal

The TrojanDropper:AutoIt/Pistolar!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:AutoIt/Pistolar!pz virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine TrojanDropper:AutoIt/Pistolar!pz?


File Info:

name: 701C4AD00D3F41E2E640.mlw
path: /opt/CAPEv2/storage/binaries/6f5dc5a5973f0baecc0987c987c5a3d106bc81e041ca47e4fee60eda84d20d6b
crc32: 2D35B89D
md5: 701c4ad00d3f41e2e640ab6a23139a92
sha1: 12da39b5d5df55d49f2306ac6b9f8337f41417ac
sha256: 6f5dc5a5973f0baecc0987c987c5a3d106bc81e041ca47e4fee60eda84d20d6b
sha512: 68af6ac98bdd47f5a7f9c616bbaf6349310f455b169bd7d5ac693d86894b3629c3412593ab712200cee61dddfe80de4ce9975d0d26ef4e327bfae7bd2724ca3b
ssdeep: 12288:9hkDgouVA2nxKkorvdRgQriDwOIxmxiZnYQE7PJcbNyj:LRmJkcoQricOIQxiZY12Nyj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T126D4AF21B5C68076C2B323B19E7EF76A9A3D79360336D29727C82D315EA05416B39733
sha3_384: 9f90d3e0f5cd8d3eb77dc078041517a52808b68d43d6ae11dd21874ac7ac4cc92c5ce7fa4d6ab11c1d2b94b3cdb230a6
ep_bytes: e816900000e989feffffcccccccccc55
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

TrojanDropper:AutoIt/Pistolar!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.Generic.8121236
FireEyeGeneric.mg.701c4ad00d3f41e2
CAT-QuickHealTrojan.AutoIt.Pistolar.A
SkyhighAutoit.Dropper.gen.a
McAfeeAutoit.Dropper.gen.a
Cylanceunsafe
VIPRETrojan.Generic.8121236
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000111 )
K7GWTrojan ( 700000111 )
Cybereasonmalicious.5d5df5
BaiduAutoIt.Worm.Agent.a
SymantecW32.SillyFDC
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
ClamAVWin.Malware.Autoit-6981134-0
KasperskyTrojan.Win32.Autoit.blz
BitDefenderTrojan.Generic.8121236
NANO-AntivirusTrojan.Script.AutoIt.dbycns
AvastAutoIt:Agent-DP [Trj]
EmsisoftTrojan.Generic.8121236 (B)
F-SecureTrojan.TR/Rogue.JH.7554630
DrWebBackDoor.IRC.Bot.3238
ZillyaWorm.AutoitGen.Win32.946
SophosW32/AutoIt-QA
IkarusWorm.Win32.AutoIt
GDataTrojan.Generic.8121236
JiangminTrojan.Generic.ixgl
GoogleDetected
AviraTR/Rogue.JH.7554630
VaristAI/Trojan.A
Antiy-AVLTrojan/Win32.Autoit
Kingsoftmalware.kb.a.991
ArcabitTrojan.Generic.D7BEB94
ZoneAlarmTrojan.Win32.Autoit.blz
MicrosoftTrojanDropper:AutoIt/Pistolar!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.AutoIt.R258728
BitDefenderThetaAI:Packer.05DA809615
ALYacTrojan.Generic.8121236
MAXmalware (ai score=80)
VBA32Trojan.Autoit
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Autoit.gen
RisingDropper.Pistolar/Autoit!1.A603 (CLASSIC)
FortinetW32/Autoit.HZ!worm
AVGAutoIt:Agent-DP [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDropper:AutoIt/Pistolar!pz?

TrojanDropper:AutoIt/Pistolar!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment