Phoenix Virus 🔐 (. Phoenix Files) — How to Remove?

What is Phoenix virus?

The scheme of renaming is this: id[xxxxxx].[contact_email].phoenix. During the encryption, a file entitled, for example, “report.docx” will be changed to “report.docx.id[1E857D00-0001].[].phoenix”.

In every directory containing the encrypted files, a info.txt text document will be found. It is a ransom money note. It contains information on the ways of contacting the racketeers and some other information. The ransom note most probably contains instructions on how to purchase the decryption tool from the tamperers. You can obtain this decrypting software after contacting via email. That is it.

NamePhoenix Virus
Ransomware family1Phobos ransomware
Extension.phoenix
Ransomware noteinfo.txt
Contact
Detection2Win32.Virlock.Gen.2, Ulise.133670, Trojan:Win32/CryptInject.CD!MTB
SymptomsYour files (photos, videos, documents) have a .phoenix extension and you can’t open them.
Fix ToolSee If Your System Has Been Affected by Phoenix virus

The info.txt file coming in package with the Phoenix malware states the following:

!!! All of your files are encrypted !!!
To decrypt them send e-mail to this address: .
If we don\'t answer in 48h., send e-mail to this address: 
If there is no response from our mail, you can install the Jabber client and write to us in support of 

In the picture below, you can see what a folder with files encrypted by the Phoenix looks like. Each filename has the “.phoenix” extension appended to it.

An example of encrypted .phoenix files.

How did Phoenix ransomware end up on my PC?

Nowadays, there are three most popular methods for hackers to have the Phoenix virus settled in your digital environment. These are email spam, Trojan injection and peer-to-peer file transfer.

If you access your mailbox and see emails that look just like notifications from utility services providers, postal agencies like FedEx, Internet providers, and whatnot, but whose sender is unknown to you, be wary of opening those emails. They are very likely to have a malware file attached to them. Thus it is even more dangerous to open any attachments that come with emails like these.

Another thing the hackers might try is a Trojan horse model3. A Trojan is an object that gets into your computer disguised as something legal. Imagine, you download an installer for some program you want or an update for some service. However, what is unpacked turns out to be a harmful agent that corrupts your data. Since the update package can have any title and any icon, you’d better be sure that you can trust the source of the things you’re downloading. The optimal way is to use the software companies’ official websites.

As for the peer-to-peer file transfer protocols like torrents or eMule, the danger is that they are even more trust-based than the rest of the Internet. You can never know what you download until you get it. Our suggestion is that you use trustworthy resources. Also, it is a good idea to scan the folder containing the downloaded files with the anti-malware utility as soon as the downloading is finished.

James H. Sterling

James H. Sterling

Environmental Science & Climate Journalist

James Sterling reports on renewable energy developments, climate policy, ecological conservation, and green tech innovations around the globe.

Share this article
Twitter Facebook Pinterest