Trojan

Trojan:Win32/Phorpiex.DSK!MTB removal instruction

Malware Removal

The Trojan:Win32/Phorpiex.DSK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phorpiex.DSK!MTB virus can do?

  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Queries information on disks, possibly for anti-virtualization
  • Detects Sandboxie through the presence of a library
  • Attempts to remove evidence of file being downloaded from the Internet
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to disable Windows Defender
  • Anomalous binary characteristics

How to determine Trojan:Win32/Phorpiex.DSK!MTB?


File Info:

crc32: ACF6883D
md5: 99440f4e89f018d32cabb6b1eba0d0d9
name: 99440F4E89F018D32CABB6B1EBA0D0D9.mlw
sha1: 9a2f86d0e30f2d1faf6afa8127e8afab35980168
sha256: c8fa09ebcc99778f406ba819df5e4c22c40d64c05567e57954d973077efee02b
sha512: 2d86ff76a7b80253ee64f8a4e097cb292362da13581a97c8864d807a83a9610923e48b1836ee5301611afedc1e7769f6b93cb8a232bb5fc466deaf76918c13c8
ssdeep: 768:Ar5bgDD5bkaiJ2XWMJnsi7/peaf1s2P522seV/d53cHrSK+9x0E3j:wiJbhiJfMxsYRbC2hVFF9KWx0O
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Phorpiex.DSK!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004ddf831 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop6.23576
ALYacDropped:Generic.Malware.SMeYBd!dld!.D9762A3D
CylanceUnsafe
ZillyaWorm.Phorpiex.Win32.735
SangforTrojan.Win32.Downloader.Gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Phorpiex.bab84cf8
K7GWTrojan ( 004ddf831 )
Cybereasonmalicious.e89f01
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Phorpiex.B
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Crypt-PQQ [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDropped:Generic.Malware.SMeYBd!dld!.D9762A3D
ViRobotTrojan.Win32.Z.Phorpiex.135168
MicroWorld-eScanDropped:Generic.Malware.SMeYBd!dld!.D9762A3D
TencentWin32.Trojan.Generic.Htls
Ad-AwareDropped:Generic.Malware.SMeYBd!dld!.D9762A3D
SophosML/PE-A
BitDefenderThetaAI:Packer.0713F3D621
VIPRETrojan.Win32.Ircbot!cobra (v)
TrendMicroTROJ_GEN.R002C0DGU21
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.cz
FireEyeGeneric.mg.99440f4e89f018d3
EmsisoftDropped:Generic.Malware.SMeYBd!dld!.D9762A3D (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.easrc
AviraTR/Downloader.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.1711D74
MicrosoftTrojan:Win32/Phorpiex.DSK!MTB
ArcabitGeneric.Malware.SMeYBd!dld!.D9762A3D
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.114P7GE
Acronissuspicious
McAfeeGenericRXFJ-DB!99440F4E89F0
MAXmalware (ai score=81)
VBA32BScope.TrojanDropper.Phorpiex
MalwarebytesMalware.AI.204571564
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DGU21
YandexTrojan.GenAsa!ZmLZSJQZwQs
IkarusWorm.Win32.Phorpiex
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Phoripex.C!tr
AVGWin32:Crypt-PQQ [Trj]
Paloaltogeneric.ml

How to remove Trojan:Win32/Phorpiex.DSK!MTB?

Trojan:Win32/Phorpiex.DSK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment