Backdoor

Backdoor.MSIL.Phoenix.j removal

Malware Removal

The Backdoor.MSIL.Phoenix.j is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MSIL.Phoenix.j virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.MSIL.Phoenix.j?


File Info:

crc32: 2DC56183
md5: fca8942d4a2b2f7faab6db8f0c04834e
name: bin2.exe
sha1: fffe7607c1309048225b0ad47ccc8a49fbb29c30
sha256: 87aabb2d251a68da0facaa40b6438b4ab73189cc0723bfc4ae289ddcf50888ca
sha512: bc87e5ebb651656990a69ec480396b45d1d2f95fadb82d439155a40637c9d503fc2789dec78bb781803149dd37cdab79f20c5c8c96202aa49740789656f8d59f
ssdeep: 24576:1u6Jx3O0c+JY5UZ+XC0kGso/WazmO5Gf6jWY:XI0c++OCvkGsUWaABY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Backdoor.MSIL.Phoenix.j also known as:

MicroWorld-eScanTrojan.GenericKD.42117110
FireEyeGeneric.mg.fca8942d4a2b2f7f
McAfeeArtemis!FCA8942D4A2B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42117110
K7GWRiskware ( 0040eff71 )
TrendMicroTROJ_FRS.VSNW0AL19
SymantecPacked.Generic.548
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.42117110
KasperskyBackdoor.MSIL.Phoenix.j
AlibabaTrojan:Win32/Predator.5fc489c4
AegisLabTrojan.MSIL.Phoenix.m!c
TencentMsil.Backdoor.Phoenix.Egoe
Ad-AwareTrojan.GenericKD.42117110
SophosTroj/Steale-FX
ComodoMalware@#3iprf9elv5b28
F-SecureDropper.DR/AutoIt.Gen8
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Downloader.th
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.42117110 (B)
CyrenW32/Trojan.PFOM-1551
MaxSecureTrojan.Malware.300983.susgen
AviraDR/AutoIt.Gen8
MAXmalware (ai score=82)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D282A7F6
ZoneAlarmBackdoor.MSIL.Phoenix.j
MicrosoftTrojan:Win32/Predator.BC!rfn
AhnLab-V3Win-Trojan/Autoinj05.Exp
ALYacTrojan.GenericKD.42117110
MalwarebytesTrojan.MalPack.AutoIt
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Packed.AutoIt.TT
TrendMicro-HouseCallTROJ_FRS.VSNW0AL19
RisingTrojan.Obfus/Autoit!1.C045 (CLASSIC)
IkarusTrojan-Spy.Keylogger.AgentTesla
FortinetAutoIt/Injector.ELS!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/Backdoor.026

How to remove Backdoor.MSIL.Phoenix.j?

Backdoor.MSIL.Phoenix.j removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment