Backdoor

Backdoor.MSIL.Phoenix.m malicious file

Malware Removal

The Backdoor.MSIL.Phoenix.m is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MSIL.Phoenix.m virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Backdoor.MSIL.Phoenix.m?


File Info:

crc32: 951C9967
md5: 63744b40e8fa9b151897240cfcbb38cb
name: mepx.exe
sha1: 86c1096cf859939e8fe96a39184a23f3d6e6822a
sha256: e1d87bc1a702bd935dbeb5edaf940274e0ff7f64ff8f616f811169e893fae76e
sha512: af749dd13a722b67d6cef14a168088ecb0b24e181e2ed125e5778b793b5895f8c0cbde07ffe24d6682af0211cdab6bc1032dc622730c9e6b282092a7e4e3650b
ssdeep: 24576:T2rT5JibBsR1YAcUSWcPsPQcVnJtCaoot6c6GUrMSuXbiKfUQt3USvD:KpJ22R1rcUWPsPFVrCaobc6OiKfUQt3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Backdoor.MSIL.Phoenix.m also known as:

MicroWorld-eScanTrojan.GenericKD.32940483
FireEyeGeneric.mg.63744b40e8fa9b15
ALYacTrojan.GenericKD.32940483
MalwarebytesTrojan.MalPack.AutoIt.Generic
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.32940483
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.cf8599
CyrenW32/Trojan.BMJU-9102
SymantecPacked.Generic.548
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Autoit-7533156-0
GDataTrojan.GenericKD.32940483
KasperskyBackdoor.MSIL.Phoenix.m
AlibabaBackdoor:MSIL/Phoenix.fb9125c0
RisingTrojan.Obfus/Autoit!1.C045 (CLASSIC)
Ad-AwareTrojan.GenericKD.32940483
SophosMal/Generic-S
ComodoMalware@#1ehwlezp3nq3
F-SecureTrojan.TR/AD.Inject.llokj
DrWebTrojan.DownLoader32.46894
ZillyaTrojan.GenericTKA.Win32.190
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
EmsisoftTrojan.GenericKD.32940483 (B)
JiangminTrojan.Pasta.ahk
WebrootW32.Malware.Gen
AviraTR/AD.Inject.llokj
Antiy-AVLTrojan/Win32.Pasta
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F6A1C3
ZoneAlarmBackdoor.MSIL.Phoenix.m
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
McAfeeArtemis!63744B40E8FA
MAXmalware (ai score=88)
VBA32Trojan.SelfDel
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.Autoit.EWB
TrendMicro-HouseCallTROJ_GEN.R020H06AD20
TencentWin32.Trojan.Autoit.Auto
eGambitUnsafe.AI_Score_100%
FortinetAutoIt/Injector.ESJ!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/Backdoor.dc1

How to remove Backdoor.MSIL.Phoenix.m?

Backdoor.MSIL.Phoenix.m removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment