Trojan

Trojan:Win32/Phorpiex.RB!MTB removal

Malware Removal

The Trojan:Win32/Phorpiex.RB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phorpiex.RB!MTB virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Phorpiex.RB!MTB?


File Info:

name: 1B0DFF1E134CAF22A544.mlw
path: /opt/CAPEv2/storage/binaries/479deede855c4145cb2089b70a36240d2a4431fe0dc46f3bdc1df8b0f4be456f
crc32: 997B2183
md5: 1b0dff1e134caf22a5448ea2dcda3701
sha1: 8522cdaaa43bdb02be5fe26b1d0d177a4bb81383
sha256: 479deede855c4145cb2089b70a36240d2a4431fe0dc46f3bdc1df8b0f4be456f
sha512: 7538d4b0fc8a2451e72c3c9d239e29263f67ab73ca497881e0824edf3c0314609571586f83eb71f541588983c266fb4793a54c569392b1d853ed25bf4b334862
ssdeep: 12288:zqIOkU8AMXE9B7PElZlP41xeVRiY4APXPV:zBOkUhMXcBwcwVU0X
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T191A46D31A6A05137D2F106B3F914D6307E7DA2187B1184ABD394AE2D3AA85D7A7F7303
sha3_384: 2c1e6d7703e2677736799938de7ef1fc57b2bcf8ce98e9618de7a500ce9c2b5e30e18d98d16c432e1252ae18426fe4eb
ep_bytes: 558bec81ec78090000e8c20c00008985
timestamp: 1970-01-01 15:50:05

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664
FileVersion: 12.0.40664.0
InternalName: setup
LegalCopyright: Copyright (c) Корпорация Майкрософт. All rights reserved.
OriginalFilename: vcredist_x86.exe
ProductName: Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664
ProductVersion: 12.0.40664.0
Translation: 0x0409 0x04e4

Trojan:Win32/Phorpiex.RB!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Patched.trwY
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.GandCrab.2689
SkyhighBehavesLike.Win32.Generic.gh
McAfeeGenericRXAA-AA!1B0DFF1E134C
Cylanceunsafe
SangforDownloader.Win32.Phorpiex.V3hs
K7AntiVirusTrojan-Downloader ( 00552edf1 )
AlibabaTrojanDownloader:Win32/Phorpiex.f97f10cf
K7GWTrojan-Downloader ( 00552edf1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Ransom.GandCrab.DA81
BitDefenderThetaGen:NN.ZexaF.36680.CG3@aCmEOKbi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.EQH
CynetMalicious (score: 100)
APEXMalicious
KasperskyTrojan.Win32.Patched.rw
BitDefenderGen:Variant.Ransom.GandCrab.2689
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:DeadZero [Inf]
TencentWin32.Trojan.Patched.Bnhl
SophosMal/Generic-S
F-SecureMalware.W32/Infector.Gen
DrWebWin32.HLLW.Autoruner3.3128
VIPREGen:Variant.Ransom.GandCrab.2689
EmsisoftGen:Variant.Ransom.GandCrab.2689 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Generic.beop
VaristW32/ZeroDloader.A.gen!Eldorado
AviraW32/Infector.Gen
MicrosoftTrojan:Win32/Phorpiex.RB!MTB
ZoneAlarmTrojan.Win32.Patched.rw
GDataWin32.Trojan.PSE.16VTW2Z
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R282625
VBA32BScope.TrojanBanker.CliptoShuffler
ALYacGen:Variant.Ransom.GandCrab.2689
TACHYONWorm/W32.ZeroDownloader
MalwarebytesGeneric.Trojan.Downloader.DDS
PandaGeneric Suspicious
RisingVirus.Phorpiex!1.E9B1 (CLASSIC)
IkarusTrojan-Downloader.Win32.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.EQH!tr
AVGWin32:DeadZero [Inf]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Phorpiex.RB!MTB?

Trojan:Win32/Phorpiex.RB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment