Trojan

Trojan:Win32/Pazzky.A removal guide

Malware Removal

The Trojan:Win32/Pazzky.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Pazzky.A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Binary compilation timestomping detected

How to determine Trojan:Win32/Pazzky.A?


File Info:

name: AC3B97B7DE819AA2943C.mlw
path: /opt/CAPEv2/storage/binaries/09c3b86af8c4bf8523e3b059888d43f79402af3ebb7fb1a30127042157748eb0
crc32: CC855B72
md5: ac3b97b7de819aa2943c4ac299876eb0
sha1: d0a72335da7cf757f3507a1e3251ba1967c1e717
sha256: 09c3b86af8c4bf8523e3b059888d43f79402af3ebb7fb1a30127042157748eb0
sha512: e79c33f2ae067df8ee1ce29ed0777dd63f46ac6d852f9ba60bcd439a344f9a41d3a9772d50bb08a35539a5a4020d6b2c1860ac4eb0ebe3a10a475ba035e81a24
ssdeep: 6144:Q2zSyBvU1FWX2B+HBvGPiXjIEYPXkDVG5OjwVJB8eTGmeDq2VA:Q2eEvroqvnXW/gjwd0mIi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EAB412A1BB90C228D355047D481B6BA857EFAC678E0F176755DCBF9DBCBA2430A03D48
sha3_384: ccba9ad541616803ac34ed40c0422e945677cd2919ad429a4ee157930964806ad31a1640f760a713619a0f288c980fbc
ep_bytes: 60be007048008dbe00a0f7ffc787a010
timestamp: 2086-07-23 20:13:06

Version Info:

0: [No Data]

Trojan:Win32/Pazzky.A also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.46280
FireEyeGeneric.mg.ac3b97b7de819aa2
CAT-QuickHealTrojan.Pazzky.A8
McAfeeTrojan-FANW!AC3B97B7DE81
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Witch.gen
K7AntiVirusTrojan ( 0040f3941 )
AlibabaWorm:Win32/Pazzky.0be5582a
K7GWTrojan ( 0040f3941 )
Cybereasonmalicious.7de819
VirITWorm.Win32.Delf.WJ
CyrenW32/A-2c759eab!Eldorado
SymantecDownloader
ESET-NOD32Win32/Delf.NHT
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Delf-17852
KasperskyHEUR:Trojan.Win32.Witch.gen
BitDefenderGen:Variant.Graftor.46280
NANO-AntivirusTrojan.Win32.Delf.bbmumv
AvastWin32:Trojan-gen
TencentWin32.Worm.Delf.Lneh
SophosW32/Delf-FOO
ComodoMalware@#2mgkcg9bkdsiv
DrWebTrojan.DownLoader4.52079
TrendMicroTROJ_SPNR.35EE13
McAfee-GW-EditionTrojan-FANW!AC3B97B7DE81
EmsisoftGen:Variant.Graftor.46280 (B)
SentinelOneStatic AI – Malicious PE
JiangminWorm/Delf.yg
AviraHEUR/AGEN.1219607
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.48B36E
KingsoftWin32.Heur.KVM007.a.(kcloud)
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Pazzky.A
ViRobotWorm.Win32.A.Delf.504792[UPX]
ZoneAlarmHEUR:Trojan.Win32.Witch.gen
GDataGen:Variant.Graftor.46280
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Downloader.R64664
VBA32TScope.Trojan.Delf
ALYacGen:Variant.Graftor.46280
MalwarebytesMalware.AI.869680209
TrendMicro-HouseCallTROJ_SPNR.35EE13
RisingTrojan.Agent!1.9D2B (CLOUD)
YandexTrojan.GenAsa!onH9OIKjX1o
IkarusTrojan-Downloader.Win32.Banload
eGambitGeneric.Malware
FortinetW32/Delf.WJ!worm
BitDefenderThetaAI:Packer.63F6FEC018
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan:Win32/Pazzky.A?

Trojan:Win32/Pazzky.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment