Trojan

TrojanDropper:Win32/Pistolar!pz (file analysis)

Malware Removal

The TrojanDropper:Win32/Pistolar!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Pistolar!pz virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to masquerade or mimic a legitimate process or file name
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDropper:Win32/Pistolar!pz?


File Info:

name: C67EEF3313DFE14722E6.mlw
path: /opt/CAPEv2/storage/binaries/a7bde239a0d998f83fae6985d2702b2ecc75f512779b2258252894290dc8174d
crc32: 70B1D41E
md5: c67eef3313dfe14722e62b7986878405
sha1: ba98cc8d2c40a785aaa4f3df5914fef20691782c
sha256: a7bde239a0d998f83fae6985d2702b2ecc75f512779b2258252894290dc8174d
sha512: 6569863188bbf07325be30a898abb3e3c5019ace2f6a00ca2ea68e5c5d3701a78de027633946f871ae319f75f984bd9c4bec3131826ee42bde0a73bc6fe3f005
ssdeep: 12288:q6Wq4aaE6KwyF5L0Y2D1PqLy6Wq4aaE6KwyF5LU:IthEVaPqLwthEE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1599412EF72A8B512D87C12B2EA430292C1B0767567FCDB7BB01075171C9F1006EAAB9D
sha3_384: dd153fbfdc4f2ace8e34c6cef12e5e07e1e323236b45e0cf7d279a94708452850cbdfc460afb74fb355f1f8eea04f3de
ep_bytes: 60be007047008dbe00a0f8ff57eb0b90
timestamp: 2012-01-29 22:49:21

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

TrojanDropper:Win32/Pistolar!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.Generic.8121236
FireEyeGeneric.mg.c67eef3313dfe147
CAT-QuickHealTrojan.AutoIt.Pistolar.A
SkyhighBehavesLike.Win32.Spyware.gc
McAfeeAutoit.Dropper.gen.a
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Generic.8121236
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000111 )
K7GWTrojan ( 700000111 )
Cybereasonmalicious.d2c40a
BaiduAutoIt.Worm.Agent.a
VirITTrojan.Win32.Autoit.ES
SymantecW32.SillyFDC
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/Autoit.HZ
APEXMalicious
ClamAVWin.Malware.Autoit-6981134-0
KasperskyTrojan.Win32.Autoit.blz
BitDefenderTrojan.Generic.8121236
NANO-AntivirusTrojan.Script.AutoIt.dbycns
AvastAutoIt:Agent-DP [Trj]
SophosW32/AutoIt-QA
F-SecureTrojan.TR/Dropper.Gen
DrWebBackDoor.IRC.Bot.3238
ZillyaTrojan.AutoIT.Win32.152520
EmsisoftTrojan.Generic.8121236 (B)
IkarusWorm.Win32.AutoIt
GDataTrojan.Generic.8121236
JiangminTrojan.MSIL.Zapchast.ag
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/AutoIt.WG.gen!Eldorado
Antiy-AVLTrojan/Win32.Graftor.fu
Kingsoftmalware.kb.b.963
XcitiumTrojWare.Win32.Autoit.n@4p0xzq
ArcabitTrojan.Generic.D7BEB94
ZoneAlarmTrojan.Win32.Autoit.blz
MicrosoftTrojanDropper:Win32/Pistolar!pz
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Autoit.305824
BitDefenderThetaAI:Packer.05DA809615
ALYacTrojan.Generic.8121236
MAXmalware (ai score=89)
VBA32Worm.Autoit.Rush
Cylanceunsafe
PandaTrj/Autoit.gen
RisingDropper.Pistolar/Autoit!1.A603 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Graftor.FU!tr
AVGAutoIt:Agent-DP [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDropper:Win32/Pistolar!pz?

TrojanDropper:Win32/Pistolar!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment