Malware

Should I remove “PWSX-gen [Trj]”?

Malware Removal

The PWSX-gen [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWSX-gen [Trj] virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Marathi
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine PWSX-gen [Trj]?


File Info:

name: 5C3DA8D07E371A976B08.mlw
path: /opt/CAPEv2/storage/binaries/0049263c94357534bcd95ff5dc9acaef0a19a18223cdeb1cb57256b63b8cbd19
crc32: D4CB7529
md5: 5c3da8d07e371a976b081d0be61a54a3
sha1: 38835ac57d942eeda19f9f8d99f88a2d01552f53
sha256: 0049263c94357534bcd95ff5dc9acaef0a19a18223cdeb1cb57256b63b8cbd19
sha512: 000c5c67da3bf60daf7d49806399b833dc8e43572cbf150e7c39a1a1eccace10e23f303b97ccae3378f49437631a35615b3d1cfede686fd7d90f32c43156054c
ssdeep: 1536:dYCACcj1sXE3RedkiXnXX0LSX2XSANJAuWCRVAD7xhe9UKwpQlrfpIvVXW+geI/C:2wcmZ1hX2T7PAD7xh3KGQUvlgeIa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19514AD2135E0D071D2F75F7068B096A15A3FBC632B74994BA6B8D67E5E307C21AB0363
sha3_384: de380132b0a188bd4872fffb6b34a2f0dcf244764d1e6ff9aed03d711dd0856469709fa5c95a2d72ba10b0db26ec353e
ep_bytes: e8c22d0000e989feffff578bc683e00f
timestamp: 2021-10-27 04:11:34

Version Info:

FileVersion: 8.71.86.86
Copyrighz: Copyright (C) 2022, pazkarte
ProjectVersion: 28.81.74.73

PWSX-gen [Trj] also known as:

BkavW32.AIDetect.malware1
CynetMalicious (score: 100)
MalwarebytesTrojan.MalPack.GS
K7AntiVirusTrojan ( 0057c3ac1 )
K7GWTrojan ( 0057c3ac1 )
Cybereasonmalicious.57d942
CyrenW32/Kryptik.GKN.gen!Eldorado
Elasticmalicious (high confidence)
APEXMalicious
ClamAVWin.Malware.Filerepmalware-9941437-0
KasperskyVHO:Trojan-PSW.MSIL.Convagent.gen
AvastPWSX-gen [Trj]
RisingTrojan.Generic@AI.98 (RDML:1cvS+lnYaBuiz6x5aKw+yA)
FireEyeGeneric.mg.5c3da8d07e371a97
SophosML/PE-A
MicrosoftTrojan:Win32/Wacatac.B!ml
SentinelOneStatic AI – Suspicious PE
AVGPWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove PWSX-gen [Trj]?

PWSX-gen [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment