Trojan

How to remove “Trojan.Win32.Povertel.ayo”?

Malware Removal

The Trojan.Win32.Povertel.ayo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Povertel.ayo virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Creates RWX memory
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Attempts to execute a powershell command with suspicious parameter/s
  • Creates a hidden or system file
  • Attempts to create or modify system certificates

Related domains:

z.whorecord.xyz
a.tomx.xyz
paste.ee

How to determine Trojan.Win32.Povertel.ayo?


File Info:

crc32: D97CAEBD
md5: 2f6110d1486ab45d4e990a584eb357ce
name: bina.jpg
sha1: 733a272dcea52674d2e03e8b2d2d960b439e71b0
sha256: 0694deb1df844c876d8b67267a811bf60a2531a8bf4cbcd77adfca4229d68648
sha512: 380ae0d26172ad1b0e7ac190f2175a6d7be2071996a94d2ab4a1888eda235f393c9b73c2e3b4be4e7c2628789c04663cc2e7437e746925ed891c7883327a4f37
ssdeep: 24576:0AHnh+eWsN3skA4RV1Hom2KXMmHaDbG5:Dh+ZkldoPK8YaDA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan.Win32.Povertel.ayo also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.2f6110d1486ab45d
Qihoo-360Win32/Trojan.7b0
ALYacBackdoor.Remcos.A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabHacktool.Win32.Gamehack.3!e
SangforMalware
K7AntiVirusTrojan-Downloader ( 0056ab9f1 )
BitDefenderTrojan.GenericKD.34391038
K7GWTrojan-Downloader ( 0056ab9f1 )
TrendMicroTROJ_GEN.R002C0DHH20
CyrenW32/AutoIt.SN.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDownloader.Autoit.OZR
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Povertel.ayo
AlibabaTrojanDownloader:Win32/Povertel.7307bb2c
MicroWorld-eScanTrojan.GenericKD.34391038
TencentWin32.Trojan.Povertel.Htwb
Ad-AwareTrojan.GenericKD.34391038
Comodo.UnclassifiedMalware@0
F-SecureHeuristic.HEUR/AGEN.1134154
Invinceaheuristic
SophosMal/Generic-S
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1134154
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/IcedId.DBC!MTB
ArcabitTrojan.Generic.D20CC3FE
ZoneAlarmTrojan.Win32.Povertel.ayo
GDataWin32.Trojan.Agent.HSSP81
AhnLab-V3Trojan/Win32.Autoit.C4182120
McAfeeArtemis!2F6110D1486A
VBA32Trojan.Wacatac
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DHH20
RisingTrojan.PSRunner/Autoit!1.C834 (CLASSIC)
IkarusTrojan-Downloader.Win32.AutoIt
eGambitUnsafe.AI_Score_93%
FortinetAutoIt/Povertel.AWH!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.dcea52
AvastWin32:Trojan-gen
MaxSecureTrojan.Malware.105468011.susgen

How to remove Trojan.Win32.Povertel.ayo?

Trojan.Win32.Povertel.ayo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment