Trojan

How to remove “Trojan.Win32.Poweliks.jrx”?

Malware Removal

The Trojan.Win32.Poweliks.jrx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Poweliks.jrx virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Poweliks.jrx?


File Info:

crc32: 06459466
md5: ad042e3cd1ff726d81f63172e55e9347
name: AD042E3CD1FF726D81F63172E55E9347.mlw
sha1: 398a362b9c6482f75a4f18cc2fb9f362ed7eb2b8
sha256: bc967c8b9180b371632af964a0fe74b403546abf6dd3299030e7cef38758b7aa
sha512: b4d603a7f7760157edfd1e85e9a41fcef954d41909693b6bf6ca879b52da1324c6ff2a058b4939253788ef2d89c675ee1488be02c8dc8df839321dc6466ad2e7
ssdeep: 3072:zzW+DiC9iLo+GnHT5ET7Np3cKAArDZz4N9GhbkrNEk1V19drXzIuYB:WKwLo7cLxyN90QEk9drXDY
type: PE32 executable (GUI) Intel 80386, for MS Windows, MS CAB-Installer self-extracting archive

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 8.00.7600.16385 (win7_rtm.090713-1255)
CompanyName: Microsoft Corporation
ProductName: Windowsxae Internet Explorer
ProductVersion: 8.00.7600.16385
FileDescription: Win32 Cabinet Self-Extractor
OriginalFilename: WEXTRACT.EXE .MUI
Translation: 0x0409 0x04b0

Trojan.Win32.Poweliks.jrx also known as:

K7AntiVirusTrojan ( 00575a1a1 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop7.12769
CynetMalicious (score: 100)
CAT-QuickHealTrojan.CrypmFC.S18890429
ALYacTrojan.GenericKD.4111654
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.31248
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 00575a1a1 )
Cybereasonmalicious.cd1ff7
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Poweliks-9843136-0
KasperskyTrojan.Win32.Poweliks.jrx
BitDefenderTrojan.GenericKD.4111654
NANO-AntivirusTrojan.Win32.Poweliks.fhyhyg
MicroWorld-eScanTrojan.GenericKD.4111654
TencentMalware.Win32.Gencirc.114b4bf9
Ad-AwareTrojan.GenericKD.4111654
SophosMal/Generic-S
ComodoMalware@#3pwj32u7rnhx5
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPCUTE.SMXF
McAfee-GW-EditionGenericRXGE-QZ!4461F37808C3
FireEyeTrojan.GenericKD.4111654
EmsisoftTrojan.GenericKD.4111654 (B)
SentinelOneStatic AI – Malicious SFX
JiangminTrojan.Crypmodadv.ep
AviraTR/Poweliks.thnot
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Genasom
ArcabitTrojan.Generic.D3EBD26
ZoneAlarmTrojan.Win32.Poweliks.jrx
GDataMSIL.Trojan-Ransom.Cryptear.O
McAfeeArtemis!AD042E3CD1FF
MAXmalware (ai score=88)
MalwarebytesRansom.FileCryptor
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CRYPCUTE.SMXF
YandexTrojan.Filecoder!Zx46lqqHN/4
FortinetMSIL/Filecoder.BQ!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Win32.Poweliks.jrx?

Trojan.Win32.Poweliks.jrx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment