Trojan

Should I remove “PowerShell/TrojanDownloader.Agent.DV”?

Malware Removal

The PowerShell/TrojanDownloader.Agent.DV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PowerShell/TrojanDownloader.Agent.DV virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Stores JavaScript or a script command in the registry, likely for persistence or configuration
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine PowerShell/TrojanDownloader.Agent.DV?


File Info:

crc32: D503F908
md5: 574125c5331d20a7bae6732a4e099807
name: 574125C5331D20A7BAE6732A4E099807.mlw
sha1: eca54341e1c3a6d31b8dba2e29020b505aee0b07
sha256: 7bc29edcbb6ab7fae89b87a34919f94988a114d522b066b0dcc223d69dbe0d57
sha512: b9f243ba1388b8e6bda0438001a91df3f7203eb0288025b5e3f33215de9836560606f1fe41f838f91df157f0c11145d2fd08874edda285b9e22c1fbade552f37
ssdeep: 1536:17fPGykbOqjoHm4pICdfkLtAfupcWX50MxFY+yIOlnToIffxdFcP77jO:hq6+ouCpk2mpcWJ0r+QNTBff/F
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PowerShell/TrojanDownloader.Agent.DV also known as:

BkavW32.CerezoAgentHAD.Trojan
MicroWorld-eScanTrojan.GenericKD.36327617
FireEyeGeneric.mg.574125c5331d20a7
McAfeeArtemis!574125C5331D
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Tiny.trFe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005036361 )
BitDefenderTrojan.GenericKD.36327617
K7GWTrojan ( 005036361 )
Cybereasonmalicious.1e1c3a
CyrenW32/Trojan.QIYA-0745
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Trojan-gen
KasperskyExploit.Win32.BypassUAC.abjz
AlibabaTrojanDownloader:BAT/BypassUAC.60a45b3c
NANO-AntivirusTrojan.Win32.DelAll.gagnzn
TencentPowershell.Trojan-downloader.Agent.Suxl
Ad-AwareTrojan.GenericKD.36327617
EmsisoftTrojan.GenericKD.36327617 (B)
ComodoMalware@#apk6bg7uns40
ZillyaTool.Lazagne.Win32.102
TrendMicroTrojan.Win32.KOCTOPUS.A
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
SophosMal/Generic-S
IkarusTrojan-Downloader.PowerShell.Agent
JiangminTrojan.PowerShell.bj
Antiy-AVLTrojan/Win32.Tiggre
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Script/Phonzy.A!ml
GridinsoftTrojan.Win32.Downloader.sa
ArcabitTrojan.Generic.D22A50C1
ZoneAlarmExploit.Win32.BypassUAC.abjz
GDataTrojan.GenericKD.36327617
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.36327617
MAXmalware (ai score=81)
MalwarebytesMalware.Heuristic.1008
ZonerTrojan.Win32.85523
ESET-NOD32PowerShell/TrojanDownloader.Agent.DV
TrendMicro-HouseCallTrojan.Win32.KOCTOPUS.A
RisingExploit.BypassUAC!8.87F5 (CLOUD)
eGambitUnsafe.AI_Score_96%
FortinetMalicious_Behavior.SB
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.BypassUAC.HwUBGaMA

How to remove PowerShell/TrojanDownloader.Agent.DV?

PowerShell/TrojanDownloader.Agent.DV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment