Trojan

PowerShell/TrojanDownloader.Agent.DCT removal tips

Malware Removal

The PowerShell/TrojanDownloader.Agent.DCT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PowerShell/TrojanDownloader.Agent.DCT virus can do?

  • Injection (inter-process)
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine PowerShell/TrojanDownloader.Agent.DCT?


File Info:

crc32: CFB4E225
md5: c7a2db955cf46991c0616000d291e5fd
name: upload_file
sha1: 763e8e3d93156b1d4ba8b612e52d215d277ec51c
sha256: b02f9d373f23a2273ee2e86a38b1d952134504f407b105e0bff1328f20791772
sha512: 87fbcc3462625d65f73b8a2264f6976eb5054204ace78c2bd6da590416ea53a4bd93c445e11378f8463f67b9170b3e387da45d3ddd4084fd5bd3239ba7208adf
ssdeep: 192:YFsFxnvX5yW61L57dMjg1m1NFrMq6FfTFgR:FPt6FJdCgs1g0R
type: ASCII text, with very long lines, with CRLF, LF line terminators

Version Info:

0: [No Data]

PowerShell/TrojanDownloader.Agent.DCT also known as:

KasperskyHEUR:Trojan.VBS.SAgent.gen
InvinceaVBS/DwnLdr-AAHN
McAfee-GW-EditionBehavesLike.VBS.Dropper.zp
SophosVBS/DwnLdr-AAHN
IkarusTrojan-Downloader.PowerShell.Agent
MicrosoftTrojan:Win32/Casdet!rfn
ZoneAlarmHEUR:Trojan.VBS.SAgent.gen
ESET-NOD32PowerShell/TrojanDownloader.Agent.DCT
Qihoo-360virus.vbs.qexvmc.1

How to remove PowerShell/TrojanDownloader.Agent.DCT?

PowerShell/TrojanDownloader.Agent.DCT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment