Trojan

TrojanAPT.Phines.WR3 information

Malware Removal

The TrojanAPT.Phines.WR3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanAPT.Phines.WR3 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine TrojanAPT.Phines.WR3?


File Info:

name: C666E2B1E1B6A073EC59.mlw
path: /opt/CAPEv2/storage/binaries/f4e9ad843b1fe029c086e903e894d526f5c7d49ad768cae2651f3eacaeb941f9
crc32: BA6C7951
md5: c666e2b1e1b6a073ec592b97842a7e60
sha1: 85d2a480f61a0fd90ee51e3d233140d42ab748f6
sha256: f4e9ad843b1fe029c086e903e894d526f5c7d49ad768cae2651f3eacaeb941f9
sha512: 9805864eceeb0e0b801d44a1662b059c702ae5c2294e61efe5214c5b4ec9a6b1328251bfc40f395a5077dc5122a85e5600195797f4ab2ef3061bb5ecb452c5fc
ssdeep: 6144:+pLBwAl9K0IeYASGqnoIP55Jxe/dcNbmqBs4oUFphi:+nr9KNeYASGqoIB5PNaqBDnhi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11F5413CA530D0118D42D58319D971FDA0EA3EBB32A90CE1FB5DA542EAEB1BD1BD646C0
sha3_384: 164ee7d07b33becd8688605dd87c6d9fb30ddcb91505a2d406adb2dd4f501037695e5e20ff77095bd9fb61c1e080a2db
ep_bytes: ff2500209fff00000000000000000000
timestamp: 2015-05-19 08:14:00

Version Info:

0: [No Data]

TrojanAPT.Phines.WR3 also known as:

BkavW32.AIDetectNet.01
LionicHeuristic.File.Generic.00×1!p
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.61274106
FireEyeGeneric.mg.c666e2b1e1b6a073
CAT-QuickHealTrojanAPT.Phines.WR3
McAfeeRDN/Real Protect-LS
CylanceUnsafe
VIPRETrojan.GenericKD.61274106
SangforSuspicious.Win32.Save.a
AlibabaTrojan:Win32/Protect.49d43e60
Cybereasonmalicious.0f61a0
CyrenW32/MSIL_Agent.BUU.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.61274106
NANO-AntivirusTrojan.Win32.Mlw.jsemls
AvastWin32:Malware-gen
TencentWin32.Trojan.Generic.Mcnw
Ad-AwareTrojan.GenericKD.61274106
EmsisoftTrojan.GenericKD.61274106 (B)
DrWebTrojan.DownLoader13.16296
ZillyaTrojan.Generic.Win32.1660419
TrendMicroTROJ_GEN.R03BC0PHF22
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.high.ml.score
SophosML/PE-A
IkarusTrojan.MSIL.Agent
GDataTrojan.GenericKD.61274106
JiangminBackdoor/Androm.jbp
AviraHEUR/AGEN.1234884
Antiy-AVLTrojan/Generic.ASMalwS.3303
ArcabitTrojan.Generic.D3A6F7FA
ViRobotTrojan.Win32.Z.Wacatac.279040.B
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Tiggre!rfn
GoogleDetected
AhnLab-V3Trojan/Win32.Dynamer.C864122
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.34646.rmW@aCc31Ff
ALYacTrojan.GenericKD.61274106
MAXmalware (ai score=81)
MalwarebytesMachineLearning/Anomalous.100%
TrendMicro-HouseCallTROJ_GEN.R03BC0PHF22
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:2gKKTB//GI/0xnLnjcMXHA)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetMSIL/Injector.JVK!tr
AVGWin32:Malware-gen
PandaTrj/Chgt.AD
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanAPT.Phines.WR3?

TrojanAPT.Phines.WR3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment