Trojan

Trojan.Win32.PowerShell.dcx malicious file

Malware Removal

The Trojan.Win32.PowerShell.dcx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.PowerShell.dcx virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Attempts to modify Windows Defender using PowerShell

How to determine Trojan.Win32.PowerShell.dcx?


File Info:

name: 88904BDB20CA958B714D.mlw
path: /opt/CAPEv2/storage/binaries/72c97850252a1dfddc7edc173a90c7c16199a5bfa0be7eb7b60adc74da7ad1b4
crc32: 1E8EBD49
md5: 88904bdb20ca958b714d4060e51f3a5a
sha1: 41511c7648666f9eb12d2e66fd61bd99cecd2200
sha256: 72c97850252a1dfddc7edc173a90c7c16199a5bfa0be7eb7b60adc74da7ad1b4
sha512: ed245e8642448537008f013363551178e03c9eee7635010d861bcb0b17fffb89e0e57d9d31f5d1e3313078ccc67d32105cbfe3d3ae0224390f41fd342c5e58f1
ssdeep: 49152:EuWnFIL+VpTW8g2yKXDqxCI3e59cUb/628euQ75VExM2AkeUKzgiqT1cOoiPBzm0:EuWFIL8g2yKT4CIO7cUO2QQ8lQ1UdmNm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EB16330276CA9BF1E5930932AF795A117C7878101F358FD7A3844B6FEE56280EE353A1
sha3_384: 91ea48f2a169fb19d7eb3afe1d28cc66804d31a4e8f3cdd3ad910a98062000e15fc61c79b0ed172b11c94f9272c32435
ep_bytes: e866050000e978feffffcccccccccccc
timestamp: 2022-01-24 07:31:18

Version Info:

0: [No Data]

Trojan.Win32.PowerShell.dcx also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Fugrafa.4!c
MicroWorld-eScanGen:Variant.Fugrafa.223728
FireEyeGeneric.mg.88904bdb20ca958b
McAfeeArtemis!88904BDB20CA
CylanceUnsafe
SangforTrojan.Script.Phonzy.C
K7GWTrojan ( 00563a1b1 )
K7AntiVirusTrojan ( 00563a1b1 )
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.PowerShell.dcx
BitDefenderGen:Variant.Fugrafa.223728
TencentWin32.Trojan.Powershell.Ecai
Ad-AwareGen:Variant.Fugrafa.223728
SophosMal/Generic-S
ZillyaTrojan.Bingoml.Win32.8340
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
EmsisoftGen:Variant.Fugrafa.223728 (B)
Paloaltogeneric.ml
GDataGen:Variant.Fugrafa.223728
Antiy-AVLTrojan/MSIL.Bladabindi
ArcabitTrojan.Fugrafa.D369F0
ViRobotTrojan.Win32.Z.Fugrafa.4039217
ZoneAlarmTrojan.Win32.PowerShell.dcx
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
CynetMalicious (score: 100)
VBA32BScope.Trojan.Meterpreter
MAXmalware (ai score=82)
MalwarebytesTrojan.Loader
TrendMicro-HouseCallTROJ_GEN.R002H09B122
AVGWin32:Malware-gen
Cybereasonmalicious.648666

How to remove Trojan.Win32.PowerShell.dcx?

Trojan.Win32.PowerShell.dcx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment