Trojan

Trojan.Win32.Povertel.aoo information

Malware Removal

The Trojan.Win32.Povertel.aoo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Povertel.aoo virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to execute a powershell command with suspicious parameter/s
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Povertel.aoo?


File Info:

crc32: 1016D5C9
md5: 2403881c19fbba7d3d19b31f69a274d6
name: webm.jpg
sha1: cda6f78b8bc7a91823e1c0f0e4c7119b1a899668
sha256: 8b68e01d79300bf9cdf8f0d0dc86dadf5281cb94d0c5ee7425a039d44c958b13
sha512: 00f9e2da1a36f265ed79774bdb3d70d4d9c129083e275fd2727970e6055ece9d2254394e7cd8ba2786a30e65f00b0e4138f65b16ce4fd852095ba998e75ffc17
ssdeep: 24576:vAHnh+eWsN3skA4RV1Hom2KXMmHazGX5:Sh+ZkldoPK8Yazq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan.Win32.Povertel.aoo also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.33545884
FireEyeGeneric.mg.2403881c19fbba7d
Qihoo-360Win32/Trojan.48c
McAfeeArtemis!2403881C19FB
K7AntiVirusTrojan ( 005625771 )
BitDefenderTrojan.GenericKD.33545884
K7GWTrojan ( 005625771 )
CrowdStrikewin/malicious_confidence_60% (W)
ArcabitTrojan.Generic.D1FFDE9C
Invinceaheuristic
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.33545884
KasperskyTrojan.Win32.Povertel.aoo
AlibabaTrojanDownloader:Win32/Povertel.f7a82fcd
AegisLabHacktool.Win32.Gamehack.3!e
Ad-AwareTrojan.GenericKD.33545884
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1044801
DrWebTrojan.Siggen9.20769
TrendMicroTROJ_GEN.R002C0PCH20
McAfee-GW-EditionBehavesLike.Win32.Downloader.ch
EmsisoftTrojan.GenericKD.33545884 (B)
IkarusTrojan-Downloader.PowerShell.Agent
AviraHEUR/AGEN.1044801
Endgamemalicious (high confidence)
ZoneAlarmTrojan.Win32.Povertel.aoo
ALYacTrojan.GenericKD.33545884
MAXmalware (ai score=88)
MalwarebytesTrojan.Injector.AutoIt
PandaTrj/CI.A
ESET-NOD32PowerShell/TrojanDownloader.Agent.CMO
TrendMicro-HouseCallTROJ_GEN.R002C0PCH20
TencentWin32.Trojan.Povertel.Hnkt
eGambitUnsafe.AI_Score_77%
FortinetAutoIt/Agent.CMO!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.b8bc7a
Paloaltogeneric.ml
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.Povertel.aoo?

Trojan.Win32.Povertel.aoo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment