Categories: Malware

What is “Win32:PWSX-gen [Trj]”?

The Win32:PWSX-gen [Trj] file is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Win32:PWSX-gen [Trj] virus can do?

  • Freezing computer.
  • New home page in browsers.
  • Ads and pop-ups on desktop and browser.
  • Very slow loading speed of webpages.
  • Computer work slower then usual.

How to determine Win32:PWSX-gen [Trj]?


General:

Operating System: Windows 7 / 8 / 8.1 / 10 Virus Name: heuristic

File Info:

Name: fox.exe

Size: 322560

Type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

MD5: 74402f5aaac7b36113db06b1d131ef2d

SHA1: 62cb43f5d539dbf848c31a561014cbac57c04fd1

SH256: 4c67ee90e0da9b323c7f1b226d249fae740a0210890196e87f1be133ae5f1f85

Version Info:

[No Data]

Win32:PWSX-gen [Trj] also known as:

ALYac DeepScan:Generic.MSIL.PasswordStealerD.B1E9DEBC
APEX Malicious
AVG Win32:PWSX-gen [Trj]
Ad-Aware DeepScan:Generic.MSIL.PasswordStealerD.B1E9DEBC
AegisLab Trojan.MSIL.Agent.4!c
AhnLab-V3 Trojan/Win32.AgentTesla.C3468286
Alibaba Backdoor:MSIL/Remcos.547185ba
Antiy-AVL Trojan/MSIL.Agent
Arcabit DeepScan:Generic.MSIL.PasswordStealerD.B1E9DEBC
Avast Win32:PWSX-gen [Trj]
Avira TR/Dropper.Gen
BitDefender DeepScan:Generic.MSIL.PasswordStealerD.B1E9DEBC
BitDefenderTheta Gen:NN.ZemsilF.32250.tm0@aOMTaKd
CAT-QuickHeal Trojan.MSIL
CrowdStrike win/malicious_confidence_100% (W)
Cybereason malicious.5d539d
Cylance Unsafe
Cyren W32/Azorult.D.gen!Eldorado
DrWeb Trojan.PWS.Siggen2.38333
ESET-NOD32 a variant of MSIL/Spy.Agent.AES
Emsisoft DeepScan:Generic.MSIL.PasswordStealerD.B1E9DEBC (B)
Endgame malicious (high confidence)
F-Prot W32/Azorult.D.gen!Eldorado
F-Secure Trojan.TR/Dropper.Gen
FireEye Generic.mg.74402f5aaac7b361
Fortinet MSIL/Agent.AES!tr.spy
GData DeepScan:Generic.MSIL.PasswordStealerD.B1E9DEBC
Ikarus Trojan.MSIL.Spy
Invincea heuristic
Jiangmin Trojan.MSIL.niul
K7AntiVirus Trojan ( 700000121 )
K7GW Trojan ( 700000121 )
Kaspersky HEUR:Trojan.MSIL.Agent.gen
MAX malware (ai score=100)
Malwarebytes Spyware.AgentTesla.MSIL
MaxSecure Trojan.Malware.300983.susgen
McAfee GenericRXII-SF!74402F5AAAC7
McAfee-GW-Edition BehavesLike.Win32.Generic.fh
MicroWorld-eScan DeepScan:Generic.MSIL.PasswordStealerD.B1E9DEBC
Microsoft Backdoor:MSIL/Remcos!MTB
Paloalto generic.ml
Panda Trj/GdSda.A
Qihoo-360 Win32/Trojan.289
Rising Spyware.AgentTesla!1.B864 (CLASSIC)
SentinelOne DFI – Malicious PE
Sophos Mal/Generic-S
Symantec ML.Attribute.HighConfidence
Trapmine malicious.moderate.ml.score
TrendMicro TROJ_GEN.R017C0DK819
TrendMicro-HouseCall TROJ_GEN.R017C0DK819
VIPRE Trojan.Win32.Generic!BT
ZoneAlarm HEUR:Trojan.MSIL.Agent.gen

How to remove Win32:PWSX-gen [Trj]?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

How to remove “Malware.AI.2670838656”?

The Malware.AI.2670838656 is considered dangerous by lots of security experts. When this infection is active,…

32 mins ago

Malware.AI.3626015347 removal

The Malware.AI.3626015347 is considered dangerous by lots of security experts. When this infection is active,…

38 mins ago

Trojan.Generic.35742373 removal instruction

The Trojan.Generic.35742373 is considered dangerous by lots of security experts. When this infection is active,…

42 mins ago

How to remove “Win32.Virtob.4.Gen”?

The Win32.Virtob.4.Gen is considered dangerous by lots of security experts. When this infection is active,…

52 mins ago

Application.Bundler.DomaIQ.Q (B) removal guide

The Application.Bundler.DomaIQ.Q (B) is considered dangerous by lots of security experts. When this infection is…

2 hours ago

Jatif.4890 information

The Jatif.4890 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago