Trojan

Trojan.Agent.PHEX.Generic (file analysis)

Malware Removal

The Trojan.Agent.PHEX.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.PHEX.Generic virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs

How to determine Trojan.Agent.PHEX.Generic?


File Info:

crc32: 8C7F8308
md5: 403874992acd8220a6bda84deb740753
name: 403874992ACD8220A6BDA84DEB740753.mlw
sha1: dfe932f63e5cac9c75b6a16609f9db99e771fb71
sha256: ad2dbbbc33a4a39a62b346ce539797f220df6b8fd1d1e41ed2671ad5b2aba671
sha512: f9c83a08b3f68ae41e1397bb4cea44242afb0ae6d618350d43c90f6de92ebdc87ee6ecefb31cd60b42361cd2673ca7a86c789d2688268d5a9368ae1f9efcbd06
ssdeep: 6144:JgmFbHB8AtHG36lSmJuePWHQZoTzOhNERR1wpT333jhHikelVBJ6:J3bh/tHGVmJl+HsoeNd330kw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Prolink Microsystems
InternalName: DarkerHushes
FileVersion: 5.2.0
CompanyName: Prolink Microsystems
ProductName: DarkerHushes
ProductVersion: 5.2.0
FileDescription: DarkerHushes
OriginalFilename: darkerhushes.exe
Translation: 0x0809 0x04b0

Trojan.Agent.PHEX.Generic also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0015e4f01 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojanPWS.Zbot.Y
ALYacGen:Variant.Symmi.838
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1336248
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojan:Win32/Bulta.650c4f84
K7GWRiskware ( 0015e4f01 )
Cybereasonmalicious.92acd8
CyrenW32/Necurs.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.AKNC
APEXMalicious
AvastWin32:Agent-APNT [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.838
NANO-AntivirusTrojan.Win32.MlwGen.baepvu
ViRobotTrojan.Win32.Z.Kryptik.352256.FU
MicroWorld-eScanGen:Variant.Symmi.838
TencentWin32.Trojan.Generic.Oyyi
Ad-AwareGen:Variant.Symmi.838
SophosML/PE-A + Mal/NecursDrp-A
ComodoTrojWare.Win32.Kryptik.AKIN@4qpr3h
F-SecureTrojan.TR/Crypt.ZPACK.Gen
BitDefenderThetaGen:NN.ZexaF.34266.vu0@aqLDkGai
VIPRELookslike.Win32.Cbeplay.p (v)
TrendMicroCryp_Necurs-1
FireEyeGeneric.mg.403874992acd8220
EmsisoftGen:Variant.Symmi.838 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.apbxi
WebrootTrojan.Dropper.Gen
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.86E103
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Necurs.A
GDataGen:Variant.Symmi.838
AhnLab-V3Spyware/Win32.Zbot.R32745
Acronissuspicious
McAfeeGeneric BackDoor.abd
MAXmalware (ai score=80)
VBA32BScope.Trojan.Necurs
MalwarebytesTrojan.Agent.PHEX.Generic
PandaTrj/Pacrypt.C
TrendMicro-HouseCallCryp_Necurs-1
RisingTrojan.Generic@ML.98 (RDML:GhKFxIm5afkh5e8vc9YzQw)
YandexTrojan.GenAsa!Z/Xs+P7tZk0
IkarusVirus.Win32.Cryptor
MaxSecureTrojan.Malware.7164915.susgen
AVGWin32:Agent-APNT [Trj]
Paloaltogeneric.ml

How to remove Trojan.Agent.PHEX.Generic?

Trojan.Agent.PHEX.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment