Malware

What is “Win32:Atraps-PZ [Trj]”?

Malware Removal

The Win32:Atraps-PZ [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Atraps-PZ [Trj] virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Win32:Atraps-PZ [Trj]?


File Info:

name: AE77FA5B267B9CE02B0C.mlw
path: /opt/CAPEv2/storage/binaries/012202205ddf1c5e565cdacf1371c4030ac6f1c07c0b33483666ca89b9f8e7d1
crc32: F8E6DC7B
md5: ae77fa5b267b9ce02b0c3455b4fc0ce8
sha1: 9f50d8a610744a2dbc9e2ac03d0e7b503c6d4ea6
sha256: 012202205ddf1c5e565cdacf1371c4030ac6f1c07c0b33483666ca89b9f8e7d1
sha512: 8c414f2ab9e3e97f864139d7b20280818e51c50e3363b8e85d4567184d2d63606bc70d4aadac4365c87c4147fbdef1a50710cc01a0e1b6419d65de19c810ef1f
ssdeep: 48:SWkO0IoyTnXz+ihZjok1ZSUrtMQ2RtB5d2lA:ZJTnXzvokSUrtIRtBP
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T13191F93B76782E67C0686B371F6754CA79EF579003680B4E88823217265A127AD7CE53
sha3_384: 22a9c9c236af852ce2e698dfb508c1cd4e679e4bab60989961cca8aa273f5c2b9cec2cedfcd333e22d892a19364e9626
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-04-07 20:00:59

Version Info:

0: [No Data]

Win32:Atraps-PZ [Trj] also known as:

BkavW32.FamVT.DebrisB.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.431082
FireEyeGeneric.mg.ae77fa5b267b9ce0
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Downloader.xt
McAfeeDownloader-FKP!AE77FA5B267B
MalwarebytesBundpil.Worm.AutoRun.DDS
VIPREGen:Variant.Barys.431082
SangforSuspicious.Win32.Save.ins
K7AntiVirusEmailWorm ( 0040f50c1 )
K7GWEmailWorm ( 0040f50c1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Worm.Bundpil.ah
VirITTrojan.Win32.Small.FAU
SymantecTrojan.Dropper
ESET-NOD32Win32/Bundpil.T
APEXMalicious
TrendMicro-HouseCallWORM_GAMARUE.SMB
ClamAVWin.Adware.Downware-246
KasperskyWorm.Win32.Debris.b
BitDefenderGen:Variant.Barys.431082
NANO-AntivirusTrojan.Win32.Drop.bqqvjw
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Atraps-PZ [Trj]
TencentTrojan.Win32.Csyr.A
EmsisoftGen:Variant.Barys.431082 (B)
GoogleDetected
F-SecureTrojan.TR/Downloader.Gen
DrWebTrojan.MulDrop4.25343
ZillyaWorm.Bundpil.Win32.1334
TrendMicroWORM_GAMARUE.SMB
Trapminesuspicious.low.ml.score
SophosW32/Gamarue-BM
SentinelOneStatic AI – Malicious PE
JiangminWorm/Generic.aftt
VaristW32/Csyr.A!Eldorado
AviraTR/Downloader.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Csyr
Kingsoftmalware.kb.a.975
MicrosoftWorm:Win32/Gamarue.DK!MTB
XcitiumWorm.Win32.Bundpil.T@4wizl6
ArcabitTrojan.Barys.D693EA
ZoneAlarmWorm.Win32.Debris.b
GDataWin32.Trojan.PSE.1Y5UO7M
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Bundpil.R63957
Acronissuspicious
BitDefenderThetaGen:NN.ZedlaF.36802.aq5@aejr6Qm
ALYacGen:Variant.Barys.431082
TACHYONWorm/W32.Debris.4485
VBA32Worm.Gamarue
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.Bundpil!1.E3E2 (CLASSIC)
IkarusWorm.Debris
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic!worm
AVGWin32:Atraps-PZ [Trj]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Gamarue.28f0ce19

How to remove Win32:Atraps-PZ [Trj]?

Win32:Atraps-PZ [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment