Trojan

Trojan-Downloader.Win32.Phpw.hzz removal guide

Malware Removal

The Trojan-Downloader.Win32.Phpw.hzz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Phpw.hzz virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Downloader.Win32.Phpw.hzz?


File Info:

name: C1C5FCFC9C0024E300D6.mlw
path: /opt/CAPEv2/storage/binaries/5466b172feb1cfbc210f973dc6cd789eed913b447edd510982a9c3f42b360692
crc32: 564CA3D4
md5: c1c5fcfc9c0024e300d6be3fcba2e4b1
sha1: fe4fcb9f339eee4696795ab46dd17b195efd18e0
sha256: 5466b172feb1cfbc210f973dc6cd789eed913b447edd510982a9c3f42b360692
sha512: e72f1f4b9cc24f77abebff49dc7074db0ffb2bad54c6430075537323ddd45cc1646fd0ad1aa5a08f1c82d77aceeb5b131e00fbe582ba3e3fb321931e2a9cc95e
ssdeep: 49152:C3dJnEwuhfyXUwNHNZpWN6DD+mSUyucrx/GFxBoD8ZJqJcDSSDcAyXiW:CTmhfyXZNtbvDqrTuA/Gf2FJcOSDol
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T142B52302FEC285F3DA620E3149296B60683CBD301F298BAFA3D85A5DC9724D1E735757
sha3_384: d142f35e46acd11e93b86c6d57bf749afdfc9f0c2ce4c0602d51358e267efb0ffe84637f8954533ffe9152dbdbe22010
ep_bytes: e8a4040000e988feffff3b0d68e64300
timestamp: 2021-04-07 14:39:21

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Phpw.hzz also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Phpw.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38099081
FireEyeGeneric.mg.c1c5fcfc9c0024e3
ALYacTrojan.GenericKD.38099081
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanDownloader:Win32/Themida.d5d08e48
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.c9c002
BitDefenderThetaGen:NN.ZedlaF.34294.iC4@auwsnLgi
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Packed.Themida.HZB
TrendMicro-HouseCallTROJ_GEN.R002H07KN21
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Phpw.hzz
BitDefenderTrojan.GenericKD.38099081
NANO-AntivirusTrojan.Win32.Phpw.itybfu
RisingTrojan.Generic@ML.92 (RDML:3OsNZZonYcCrhrLL+/oKxw)
Ad-AwareTrojan.GenericKD.38099081
EmsisoftTrojan.GenericKD.38099081 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosMal/Generic-S
GDataTrojan.GenericKD.38099081
AviraTR/Dldr.Agent.vfari
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.3091916
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!C1C5FCFC9C00
VBA32TrojanDownloader.Phpw
PandaTrj/CI.A
APEXMalicious
TencentWin32.Trojan-downloader.Phpw.Syhp
YandexTrojan.DL.Phpw!3PgK1rwRXz8
FortinetW32/Generic!tr.dldr
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]

How to remove Trojan-Downloader.Win32.Phpw.hzz?

Trojan-Downloader.Win32.Phpw.hzz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment