Trojan

Trojan.Win32.Povertel.ays malicious file

Malware Removal

The Trojan.Win32.Povertel.ays is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Povertel.ays virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to execute a powershell command with suspicious parameter/s
  • Creates a hidden or system file

Related domains:

paste.ee

How to determine Trojan.Win32.Povertel.ays?


File Info:

crc32: FA9C3145
md5: 85f15f0b7f5da288792028ba8fe3ffb9
name: 5by8.jpg
sha1: 5be66b55d1f310072c8889f572e96bac99304777
sha256: 1034661e0e25d714e86a61237951a4359950398a1f129486da4745bbd9e6242b
sha512: 89b76f7c64707149f04dbb06567ad48f74c6883bd1e06281343a9a3afc59e7444427420c93bb8c136a99dabb6c0ff3561b29391dce21d6c66b3a563f5b31c59d
ssdeep: 24576:ZAHnh+eWsN3skA4RV1Hom2KXMmHaJ4Q5:gh+ZkldoPK8YaJX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan.Win32.Povertel.ays also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34410568
FireEyeGeneric.mg.85f15f0b7f5da288
CAT-QuickHealTrojan.Multi
McAfeeArtemis!85F15F0B7F5D
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabHacktool.Win32.Gamehack.3!e
SangforMalware
K7AntiVirusTrojan-Downloader ( 0056ab9f1 )
BitDefenderTrojan.GenericKD.34410568
K7GWTrojan-Downloader ( 0056ab9f1 )
TrendMicroTROJ_GEN.R002C0DHJ20
CyrenW32/AutoIt.SN.gen!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Povertel.ays
AlibabaTrojanDownloader:Win32/Povertel.64bde256
ViRobotTrojan.Win32.Z.Povertel.868352.C
RisingTrojan.PSRunner/Autoit!1.C834 (CLASSIC)
Ad-AwareTrojan.GenericKD.34410568
SophosMal/Generic-S
Comodo.UnclassifiedMalware@0
F-SecureHeuristic.HEUR/AGEN.1134154
Invinceaheuristic
EmsisoftTrojan.GenericKD.34410568 (B)
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1134154
MAXmalware (ai score=81)
MicrosoftTrojanDownloader:AutoIt/Povertel.G!MTB
ArcabitTrojan.Generic.D20D1048
ZoneAlarmTrojan.Win32.Povertel.ays
GDataTrojan.GenericKD.34410568
CynetMalicious (score: 100)
VBA32Trojan.Wacatac
ALYacTrojan.GenericKD.34410568
ESET-NOD32a variant of Win32/TrojanDownloader.Autoit.OZR
TrendMicro-HouseCallTROJ_GEN.R002C0DHJ20
TencentWin32.Trojan.Povertel.Eddx
IkarusTrojan-Downloader.Win32.AutoIt
MaxSecureTrojan.Malware.105528049.susgen
FortinetAutoIt/Povertel.AWH!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.5d1f31
PandaTrj/CI.A
Qihoo-360Win32/Trojan.078

How to remove Trojan.Win32.Povertel.ays?

Trojan.Win32.Povertel.ays removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment