Trojan

Trojan.Win32.PowerShell.cyv information

Malware Removal

The Trojan.Win32.PowerShell.cyv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.PowerShell.cyv virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Created a process from a suspicious location
  • A script process created a new process

How to determine Trojan.Win32.PowerShell.cyv?


File Info:

name: F5348421D46972D15E25.mlw
path: /opt/CAPEv2/storage/binaries/03614d528809171ea45459ac44783c841827e663322e3fdfe5b3e2477d47a160
crc32: 0D4C7533
md5: f5348421d46972d15e25f871bc07ecc2
sha1: 760074b351752bf974c8726ffde399b71cde0edf
sha256: 03614d528809171ea45459ac44783c841827e663322e3fdfe5b3e2477d47a160
sha512: a2048a727dff331c486ff12ae289b56619cc3fc4f6ad60f94195c53f86287cac8b87f20b259dd8a6380ab06a68179b8a873b97febdbdbbfc0d87998436fe3858
ssdeep: 12288:0Qnk3GDYKGcblwtX+t4Y8v1gZpg33B3XIOMeb9Xg8xgernDi5kivGXk6rM2:IAOcZwXYE1pB3XIOMG1pgerDgkgtOp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T160050201BBC188B1E4731C325A296F266D3D7C202E25DF6FB3E4796DDA35081A624B77
sha3_384: 9131c550bfa860abaefb4e5610885a96cf132df796816fd5639e079afbc4c92b6683b3d3ebcbaa9bb1151c6c346cecf5
ep_bytes: e89a040000e98efeffff3b0d68d64300
timestamp: 2020-03-26 10:02:47

Version Info:

0: [No Data]

Trojan.Win32.PowerShell.cyv also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.PowerShell.4!c
ALYacTrojan.GenericKD.38200228
MalwarebytesMalware.AI.4037402633
AlibabaTrojan:Win32/PowerShell.a63e941d
Cybereasonmalicious.351752
CyrenW32/S-536dd2d1!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Filecoder.FV
TrendMicro-HouseCallTROJ_FRS.VSNTL721
AvastFileRepMetagen [Malware]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.PowerShell.cyv
BitDefenderTrojan.GenericKD.38200228
MicroWorld-eScanTrojan.GenericKD.38200228
Ad-AwareTrojan.GenericKD.38200228
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Agent.zmodc@0
TrendMicroTROJ_FRS.VSNTL721
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
FireEyeGeneric.mg.f5348421d46972d1
EmsisoftTrojan.GenericKD.38200228 (B)
Paloaltogeneric.ml
GDataTrojan.GenericKD.38200228
AviraTR/PShell.thkia
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D246E3A4
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.Generic.C4818131
McAfeeRDN/Generic
MAXmalware (ai score=84)
CylanceUnsafe
APEXMalicious
eGambitUnsafe.AI_Score_63%
AVGFileRepMetagen [Malware]
MaxSecureWin.MxResIcn.Heur.Gen

How to remove Trojan.Win32.PowerShell.cyv?

Trojan.Win32.PowerShell.cyv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment