In this message, I am going to clarify how the Powdown trojan infused right into your PC, and also how to clear away Powdown trojan virus.
What is Powdown trojan?
Name | Powdown |
Infection Type | Trojan |
Symptoms |
|
Similar behavior | Rastreio, Rastreio, XDSpy, Gena, Sulee, Alkhaser |
Fix Tool | See If Your System Has Been Affected by Powdown trojan |
Trojan viruses are one of the leading malware types by its injection frequency for quite a very long time. And currently, during the pandemic, when malware became tremendously active, trojan viruses increased their activity, too. You can see lots of messages on diverse websites, where users are grumbling concerning the Powdown trojan virus in their computers, and also requesting for assistance with Powdown trojan virus clearing.
Trojan Powdown is a sort of virus that injects right into your personal computer, and after that performs different malicious functions. These features rely on a kind of Powdown trojan: it can function as a downloader for additional malware or as a launcher for an additional harmful program which is downloaded together with the Powdown trojan. During the last 2 years, trojans are additionally delivered using e-mail attachments, and most of instances utilized for phishing or ransomware injection.
Powdown2 also known as
Bkav | W32.AIDetectMalware |
Lionic | Trojan.Win32.Povertel.4!c |
MicroWorld-eScan | Trojan.GenericKD.32070419 |
FireEye | Trojan.GenericKD.32070419 |
McAfee | RDN/Generic Downloader.x |
Cylance | unsafe |
VIPRE | Trojan.GenericKD.32070419 |
Sangfor | Backdoor.Win32.APT33.ulxpg |
K7AntiVirus | Trojan ( 00550a851 ) |
Alibaba | TrojanDownloader:Win32/Povertel.948dcd36 |
K7GW | Trojan ( 00550a851 ) |
Cybereason | malicious.075657 |
Cyren | W32/Trojan.BLWO-1722 |
Symantec | Trojan Horse |
ESET-NOD32 | PowerShell/TrojanDownloader.Agent.BSO |
APEX | Malicious |
Kaspersky | Trojan.Win32.Povertel.aez |
BitDefender | Trojan.GenericKD.32070419 |
NANO-Antivirus | Trojan.Win32.Povertel.frovml |
Avast | Win32:Trojan-gen |
Tencent | Win32.Trojan-Downloader.Downloader.Rqil |
Sophos | Mal/Generic-R |
TrendMicro | Trojan.Win32.DLOADR.AUSUQH |
McAfee-GW-Edition | RDN/Generic Downloader.x |
Trapmine | malicious.moderate.ml.score |
Emsisoft | Trojan.GenericKD.32070419 (B) |
GData | Trojan.GenericKD.32070419 |
Jiangmin | Trojan.Povertel.o |
Webroot | W32.Trojan.Gen |
Detected | |
Antiy-AVL | Trojan/Win32.Apt33 |
Xcitium | Malware@#3d7yeas7rpfy0 |
Arcabit | Trojan.Generic.D1E95B13 |
ViRobot | Trojan.Win32.S.Agent.873904 |
ZoneAlarm | Trojan.Win32.Povertel.aez |
Microsoft | TrojanDownloader:Win32/Powdown |
AhnLab-V3 | Trojan/Win32.Povertel.C3293969 |
BitDefenderTheta | AI:Packer.1B0ACE3717 |
ALYac | Trojan.Agent.Povertel |
MAX | malware (ai score=82) |
VBA32 | Trojan.Povertel |
Malwarebytes | Generic.Malware/Suspicious |
Panda | Trj/CI.A |
TrendMicro-HouseCall | Trojan.Win32.DLOADR.AUSUQH |
Ikarus | Trojan-Downloader.PowerShell.Agent |
Fortinet | W32/Povertel.AEZ!tr |
AVG | Win32:Trojan-gen |
DeepInstinct | MALICIOUS |
CrowdStrike | win/malicious_confidence_100% (W) |
What are the symptoms of Powdown trojan?
- Behavioural detection: Executable code extraction – unpacking;
- A file was accessed within the Public folder.;
- Sample contains Overlay data;
- Presents an Authenticode digital signature;
- CAPE extracted potentially suspicious content;
- Executed a very long command line or script command which may be indicative of chained commands or obfuscation;
- Authenticode signature is invalid;
- A scripting utility was executed;
- A script or command line contains a long continuous string indicative of obfuscation;
- Attempts to execute suspicious powershell command arguments;
- Anomalous binary characteristics;
- Yara rule detections observed from a process memory dump/dropped files/CAPE;
The common symptom of the Powdown trojan virus is a gradual appearance of a wide range of malware – adware, browser hijackers, et cetera. Because of the activity of these destructive programs, your computer ends up being really sluggish: malware utilizes substantial quantities of RAM and CPU capacities.
An additional noticeable result of the Powdown trojan virus presence is unidentified processes showed off in task manager. Often, these processes might attempt to simulate system processes, but you can understand that they are not legit by looking at the origin of these processes. Quasi system applications and Powdown trojan’s processes are always listed as a user’s tasks, not as a system’s.
How to remove Powdown trojan virus?
- Download and install Loaris Trojan Remover.
- Open Loaris and perform a “Standard scan“.
- “Move to quarantine” all items.
- Open “Tools” tab – Press “Reset Browser Settings“.
- Approve the reset pressing “Yes” button in the appeared window.
- Restart your computer.
To remove Powdown trojan and ensure that all satellite malware, downloaded with the help of this trojan, will certainly be wiped out, as well, I’d advise you to use Loaris Trojan Remover.
Powdown removal guide
To spot and eliminate all viruses on your personal computer using Loaris, it’s better to use Standard or Full scan. Removable scan, as well as Custom, will check only specified directories, so such checks are not able to provide the full information.
You can observe the detects during the scan process goes. However, to perform any actions against detected malicious programs, you need to wait until the process is finished, or to stop the scanning process.
To choose the appropriate action for each detected viruses, click the button in front of the detection name of detected viruses. By default, all malware will be sent to quarantine.
How to remove Powdown Trojan?
Name: Powdown
Description: Trojan Powdown is a kind of virus that infiltrates into your computer, and after that performs different destructive functions. These features depend upon a type of Powdown trojan: it can act as a downloader for many other malware or as a launcher for another destructive program which is downloaded in addition to the Powdown trojan. During the last two years, trojans are also dispersed via e-mail attachments, and most of situations utilized for phishing or ransomware infiltration.
Operating System: Windows
Application Category: Trojan
User Review
( votes)- What is Trojan Horse: https://en.wikipedia.org/wiki/Trojan_horse_(computing)
- Powdown VirusTotal Report: https://www.virustotal.com/api/v3/files/79b6116eb59e60c0cd0a4b9005161141d30ab91ce5076c9b4d19bfd4e84c3a29