Trojan

About “Trojan:Win32/Phorpiex.MLN!MTB” infection

Malware Removal

The Trojan:Win32/Phorpiex.MLN!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phorpiex.MLN!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Attempts to connect to a dead IP:Port (5 unique times)
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Trojan:Win32/Phorpiex.MLN!MTB?


File Info:

crc32: 2E05E2A9
md5: d7671ba3b6e42855af4cfb3d44cedc80
name: vps.exe
sha1: 7b13c2ee2a1fc8bc8949eb1f21f405ce980edb0d
sha256: 452f364e317c79a370cd9b16e52f01971e981ffd9948d69d6457196711218f6f
sha512: 8033a89bd28c2801b44529c5fe10123f2163155f79d7fd7f02be3e0e93e9d1f022c62e179fa32843b6b0a66d0b32c85b53f9a0ccf3b7029d80028d9bd10961fe
ssdeep: 12288:Kr6NVWqmK7h/zh66GorfVGRmp5+l2PJmY3W:a6NxmK7h7hjGorfVxIEPUk
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Phorpiex.MLN!MTB also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.33545308
FireEyeGeneric.mg.d7671ba3b6e42855
Qihoo-360Win32/Trojan.BO.336
McAfeeArtemis!D7671BA3B6E4
ALYacTrojan.Trickster.Gen
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33545308
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.e2a1fc
BitDefenderThetaGen:NN.ZexaF.34100.KOW@aO9zopE
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:CoinminerX-gen [Trj]
GDataTrojan.GenericKD.33545308
KasperskyTrojan-Banker.Win32.Danabot.ehk
AegisLabRiskware.Win32.Malicious.1!c
TencentWin32.Trojan-banker.Danabot.Wrgh
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.Agent.ivyey
DrWebTrojan.Siggen9.21268
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.hc
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.33545308 (B)
IkarusTrojan.Win32.Krypt
CyrenW32/CoinMiner.BL.gen!Eldorado
JiangminTrojan/Obfuscated.envk
AviraTR/Crypt.Agent.ivyey
MAXmalware (ai score=83)
ArcabitTrojan.Generic.D1FFDC5C
ZoneAlarmTrojan-Banker.Win32.Danabot.ehk
MicrosoftTrojan:Win32/Phorpiex.MLN!MTB
AhnLab-V3Trojan/Win32.MalPe.R328801
Acronissuspicious
Ad-AwareTrojan.GenericKD.33545308
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HBYC
TrendMicro-HouseCallTROJ_GEN.R011H0CCG20
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojan.Kryptik!rAAGySKaXyQ
SentinelOneDFI – Malicious PE
FortinetW32/Kryptik.HBYC!tr
AVGWin32:CoinminerX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Phorpiex.MLN!MTB?

Trojan:Win32/Phorpiex.MLN!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment