Malware

About “BV:Downloader-MA [Trj]” infection

Malware Removal

The BV:Downloader-MA [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BV:Downloader-MA [Trj] virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • A script or command line contains a long continuous string indicative of obfuscation

How to determine BV:Downloader-MA [Trj]?


File Info:

name: CF66220581B2F9661AE0.mlw
path: /opt/CAPEv2/storage/binaries/6afa82637c2b9b6d2a469b2a33a8a79eea1ff73e3ac646ff44a19f62fc7d942b
crc32: D24E0911
md5: cf66220581b2f9661ae0c49bc3015e22
sha1: eaa278a7ce0e3d6b85a98bf8675f258d89c4ff9e
sha256: 6afa82637c2b9b6d2a469b2a33a8a79eea1ff73e3ac646ff44a19f62fc7d942b
sha512: be0dbe254f05fd0283c61ee166da8b620062a7d83aa019ca4dd63c01b6e46e08324eb1b09ae665176d6cfce11a82bc4a66a0b5c97a1f77fd8bc1625505e08c5d
ssdeep: 6144:tbJhs7QW69hd1MMdxPe9N9uA0hu9TBmgtV:tbjDhu9ToeV
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1B814F646E290114DCBB954F6C8B247079F7074B11F60A3DB17AD7AB2173788A8B6D393
sha3_384: 7b31ee8d6c45108137b40fe0ab40a86e8c5de90cecba4b174ce7be0f01271e55ac8a30c3b26ed3285074f2a88c6bd55d
ep_bytes: 4883ec2849c7c0600100004831d248b9
timestamp: 2018-02-01 19:43:24

Version Info:

0: [No Data]

BV:Downloader-MA [Trj] also known as:

LionicTrojan.Win32.PwShell.4!c
MicroWorld-eScanDropped:Trojan.PwShell.Downloader.B
FireEyeGeneric.mg.cf66220581b2f966
ALYacDropped:Trojan.PwShell.Downloader.B
CylanceUnsafe
K7AntiVirusTrojan ( 00501e431 )
AlibabaTrojan:Win32/PowerShell.c9a3eaca
K7GWTrojan ( 00501e431 )
Cybereasonmalicious.581b2f
CyrenW64/Kryptik.FDL.gen!Eldorado
SymantecDownloader
ESET-NOD32PowerShell/Rozena.AF
Paloaltogeneric.ml
KasperskyTrojan.Win32.PowerShell.cyo
BitDefenderDropped:Trojan.PwShell.Downloader.B
AvastBV:Downloader-MA [Trj]
Ad-AwareDropped:Trojan.PwShell.Downloader.B
EmsisoftDropped:Trojan.PwShell.Downloader.B (B)
McAfee-GW-EditionBehavesLike.Win64.Dropper.cm
SophosMal/Generic-R
SentinelOneStatic AI – Malicious PE
GDataDropped:Trojan.PwShell.Downloader.B
AviraTR/B2E.Dropper.Gen
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.C4827032
McAfeeRDN/Generic Downloader.x
MalwarebytesTrojan.Meterpreter
APEXMalicious
YandexTrojan.PowerShell!ibjZUfWXHAE
IkarusTrojan.PowerShell.Rozena
MaxSecureTrojan.Malware.300983.susgen
FortinetPowerShell/Rozena.AF!tr
AVGBV:Downloader-MA [Trj]

How to remove BV:Downloader-MA [Trj]?

BV:Downloader-MA [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment