Trojan

PowerShell/TrojanDownloader.Agent.EQN removal guide

Malware Removal

The PowerShell/TrojanDownloader.Agent.EQN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PowerShell/TrojanDownloader.Agent.EQN virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine PowerShell/TrojanDownloader.Agent.EQN?


File Info:

name: 91667F06EF68715A5096.mlw
path: /opt/CAPEv2/storage/binaries/58ac5e016a7934915f604b3d68322d8f300451a7c6b2f38686523f5f8f5bc289
crc32: 6EB8E057
md5: 91667f06ef68715a5096d386897c8e3d
sha1: 9f86bb9e6235a86f94937fb943b9fc75d45b2c02
sha256: 58ac5e016a7934915f604b3d68322d8f300451a7c6b2f38686523f5f8f5bc289
sha512: 788275b830a29db81c9274895208b33a161fb74680eee71fa2ee05fa87b85678099997ed7df2ea39a1fc8121ef64c7dc69936d85703d7991b9d795805d433eec
ssdeep: 12288:mToPWBv/cpGrU3yq3tOJUO9+at7Iwc+x0ezqPj9B:mTbBv5rUMUO7MwcG+Pj9B
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T168D40203FAD18872C47319365B297B22653DB6201FA58ECBA7D44E6DEE312D0FB31691
sha3_384: ba9d2908bbf26145fb4fee12ab6f7d883d546824ae3a5323a477a345c7822fbf0e6bd1f47b4f786efc9597a30f8c73cb
ep_bytes: e866050000e978feffffcccccccccccc
timestamp: 2022-03-03 13:15:57

Version Info:

0: [No Data]

PowerShell/TrojanDownloader.Agent.EQN also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Dapato.b!c
MicroWorld-eScanTrojan.GenericKD.60047169
ALYacTrojan.GenericKD.60047169
CylanceUnsafe
SangforTrojan.Win32.Dapato.qzpk
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32PowerShell/TrojanDownloader.Agent.EQN
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Fugrafa-9938779-0
KasperskyTrojan-Dropper.Win32.Dapato.qzpk
BitDefenderTrojan.GenericKD.60047169
TencentWin32.Trojan-downloader.Agent.Hres
Ad-AwareTrojan.GenericKD.60047169
EmsisoftTrojan.GenericKD.60047169 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.91667f06ef68715a
SophosMal/Generic-S
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D3943F41
GDataWin32.Trojan-Downloader.Generic.O07902
CynetMalicious (score: 100)
Acronissuspicious
McAfeeRDN/Generic Dropper
MAXmalware (ai score=88)
TrendMicro-HouseCallTROJ_GEN.R002H0DE622
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove PowerShell/TrojanDownloader.Agent.EQN?

PowerShell/TrojanDownloader.Agent.EQN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment