Trojan

What is “Trojan.Win32.PowerShell.cyz”?

Malware Removal

The Trojan.Win32.PowerShell.cyz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.PowerShell.cyz virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Created a process from a suspicious location
  • A script process created a new process

How to determine Trojan.Win32.PowerShell.cyz?


File Info:

name: 9E409AEE03E4F87E9713.mlw
path: /opt/CAPEv2/storage/binaries/82c21a7b1ec84dd371d8c405dddc412cc16d8b8b0457a0ee2cdd69766a1a54a2
crc32: 88089A62
md5: 9e409aee03e4f87e971302590eb9077e
sha1: 53e7338ed6a087f2d0b35a560e77d7b24f0ad85e
sha256: 82c21a7b1ec84dd371d8c405dddc412cc16d8b8b0457a0ee2cdd69766a1a54a2
sha512: f49b03dd953377ed5b8fc42fcc58c970d15c54df4dea3cf76bc9578d415acc60426ed45ef466c322e3ea9da5c8ae09031d255a9b52ceac2b871f0539269d6d86
ssdeep: 12288:0Qnk3GDYKGcblwtX+t4Y8nX/2wEKVf3tBBaADb56p9x7xGZPhmhZGpntS/gLfXA0:IAOcZwXYuPXEK9trt6p9x7I9g/+1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11F050201BAD2C572D5330D365A29AB256D7DBD201F34DB2EA7D46D2EDA301C1A338B63
sha3_384: b86787b2dc84f8144171ec97f5f0dec4a0279243bbda9401715a1debdb2e4c903099ee62f9aa861fe8b360fa68dcc2fa
ep_bytes: e89a040000e98efeffff3b0d68d64300
timestamp: 2020-03-26 10:02:47

Version Info:

0: [No Data]

Trojan.Win32.PowerShell.cyz also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.PowerShell.4!c
MicroWorld-eScanIL:Trojan.MSILZilla.11801
FireEyeGeneric.mg.9e409aee03e4f87e
McAfeeArtemis!9E409AEE03E4
CylanceUnsafe
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojan:Win32/PowerShell.7dd9a0de
Cybereasonmalicious.ed6a08
CyrenW32/S-536dd2d1!Eldorado
SymantecTrojan.Gen.MBT
Paloaltogeneric.ml
KasperskyTrojan.Win32.PowerShell.cyz
BitDefenderIL:Trojan.MSILZilla.11801
AvastWin32:Malware-gen
TencentWin32.Trojan.Powershell.Hviu
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
EmsisoftIL:Trojan.MSILZilla.11801 (B)
GDataIL:Trojan.MSILZilla.11801
AviraTR/PShell.umxne
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
ALYacIL:Trojan.MSILZilla.11801
MAXmalware (ai score=80)
MalwarebytesMalware.AI.4037402633
APEXMalicious
MaxSecureWin.MxResIcn.Heur.Gen
AVGWin32:Malware-gen

How to remove Trojan.Win32.PowerShell.cyz?

Trojan.Win32.PowerShell.cyz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment