Malware

Win32:Pixoliz-AN [Trj] removal instruction

Malware Removal

The Win32:Pixoliz-AN [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Pixoliz-AN [Trj] virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Win32:Pixoliz-AN [Trj]?


File Info:

name: E7A4CF61B9CEAB8BEDB0.mlw
path: /opt/CAPEv2/storage/binaries/2cb4a9455e2dc50ce159f821cf03c54d05794307b40c659403333d65157017cd
crc32: D67C1846
md5: e7a4cf61b9ceab8bedb0151d175607c2
sha1: 263ac418a9c7e1b7bbf610c74411712e2ce4b1da
sha256: 2cb4a9455e2dc50ce159f821cf03c54d05794307b40c659403333d65157017cd
sha512: fb1e4cbd71e2c393eb41718c0940a9fbfa065758a8600e2e644c1bba6ee793f8c77e51f8e3ffe3b121ab5bba77216b42ac73c85484c91e8e4ae415366c48b3fc
ssdeep: 6144:76bhNflfEK4UJx1SKxJ+61b88bkhkEjWbjcSbcY+CaQdaFOY4iGFYtR:Gbh9lfEjUJx1SKxs61b6kFbz+xt4vF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T115A4CF81FA50C097D46F86315CE1C689176CBC16FFA163EB7268BF6F58761C1A83039A
sha3_384: 0aa46d08792def8a5e26125157be77bef44bec067c78f82b9447514d038165f187ad373125d277067c18963e94b044e1
ep_bytes: 60b99c3102008a91ff0f400080eadd88
timestamp: 2007-06-02 06:27:43

Version Info:

CompanyName: TODO:
FileDescription: TODO:
FileVersion: 1.0.0.1
InternalName: AdwTest.exe
LegalCopyright: TODO: (c) . All rights reserved.
OriginalFilename: AdwTest.exe
ProductName: TODO:
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04e4

Win32:Pixoliz-AN [Trj] also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.CQST
FireEyeGeneric.mg.e7a4cf61b9ceab8b
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.gh
McAfeeGenericR-CVM!E7A4CF61B9CE
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Agent.CQST
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005ac2dd1 )
K7GWTrojan ( 005ac2dd1 )
Cybereasonmalicious.1b9cea
ArcabitTrojan.Agent.CQST
VirITTrojan.Win32.MulDrop5.CKMW
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Agent.WTK
APEXMalicious
ClamAVWin.Malware.Razy-9759519-0
KasperskyHEUR:Trojan.Win32.Nobady.pef
BitDefenderTrojan.Agent.CQST
NANO-AntivirusTrojan.Win32.Mlw.fjftld
AvastWin32:Pixoliz-AN [Trj]
TencentTrojan.Win32.Agent.zl
EmsisoftTrojan.Agent.CQST (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen7
DrWebTrojan.MulDrop5.42246
ZillyaTrojan.AgentGen.Win32.95
SophosMal/Agent-AWE
IkarusTrojan.Win32.Aenjaris
JiangminTrojan.Agent.dulc
GoogleDetected
AviraTR/Crypt.ZPACK.Gen7
VaristW32/S-6053bf39!Eldorado
Antiy-AVLTrojan/Win32.Agent.wtk
Kingsoftmalware.kb.a.981
XcitiumTrojWare.Win32.Aenjaris.ABC@8hq1l4
MicrosoftTrojan:Win32/Aenjaris.AL!bit
ZoneAlarmHEUR:Trojan.Win32.Nobady.pef
GDataWin32.Trojan.BadJoke.J
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R136020
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36802.Cq3@aiRt5@ai
ALYacTrojan.Agent.CQST
MAXmalware (ai score=89)
VBA32SScope.Malware-Cryptor.Aenjaris
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Agent!1.A728 (CLASSIC)
YandexTrojan.Agent!iN2uAMbdw10
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Agent.antno
FortinetW32/Agent.WTK!tr
AVGWin32:Pixoliz-AN [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudRiskWare:Win/Agent.888aec4a

How to remove Win32:Pixoliz-AN [Trj]?

Win32:Pixoliz-AN [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment