Trojan

How to remove “Trojan.Powershell”?

Malware Removal

The Trojan.Powershell is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Powershell virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Powershell?


File Info:

crc32: 233EC76B
md5: 7225885fe2958a62398e59a279fdb857
name: signed.exe
sha1: 16a30106f75f4c9ee0907fe115ba09ec91d38d5c
sha256: 9034bea1bee5769d7bcdb36f44160fc7c4037a0f0a3a0b5e4a741d80c296dde2
sha512: bc0580396c14cb0a3ef17009628b1011221214f014c169fff43b4e13fe9d9af5a4d567aa2fee165a5e1edef35e681a3291d543cfeb3a6af038a83df68baf24a4
ssdeep: 98304:SJuQda3jrp31kj1MuedJ16RuAtU0XHZkeegL9PRoG1wriYB5M4nYtzFoxUCemwbV:6tdaB3yjuuMJ1xcptzVS6/1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: all rights reserved
FileVersion: 2.2.2.1
CompanyName: update new version llc
LegalTrademarks: copyright zugmuwywrv all rights
Comments: internet update
ProductName: update of new version software
Translation: 0x0409 0x04e4

Trojan.Powershell also known as:

MicroWorld-eScanTrojan.GenericKD.42332963
FireEyeTrojan.GenericKD.42332963
CAT-QuickHealTrojan.Powershell
McAfeeArtemis!7225885FE295
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Agentb.tpDn
K7AntiVirusTrojan ( 005528ea1 )
BitDefenderTrojan.GenericKD.42332963
K7GWTrojan ( 005528ea1 )
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.42332963
KasperskyHEUR:Trojan.PowerShell.Generic
AlibabaTrojan:Application/based.ceee6798
NANO-AntivirusTrojan.Win32.PowerShell.gydzjj
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.42332963 (B)
F-SecureMalware.VBS/PShell.fpvwx
DrWebPowerShell.Dropper.10
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
CyrenW32/Trojan.RYWQ-4650
JiangminTrojan.Agent.bzgs
WebrootW32.Trojan.Gen
AviraVBS/PShell.fpvwx
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Generic.D285F323
ZoneAlarmHEUR:Trojan.PowerShell.Generic
VBA32Trojan.Wacatac
ALYacTrojan.PowerShell.Agent
Ad-AwareTrojan.GenericKD.42332963
MalwarebytesTrojan.MalPack
PandaTrj/CI.A
ESET-NOD32PowerShell/RA-based.A
TrendMicro-HouseCallTROJ_GEN.R023H0DB220
RisingTrojan.ScriptRunner/NSIS!1.BD6D (CLASSIC)
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/Trojan.d6f

How to remove Trojan.Powershell?

Trojan.Powershell removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment