Trojan

Should I remove “Trojan.PhonzyPMF.S18532810”?

Malware Removal

The Trojan.PhonzyPMF.S18532810 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.PhonzyPMF.S18532810 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

How to determine Trojan.PhonzyPMF.S18532810?


File Info:

name: 25AFC210A36230DA7199.mlw
path: /opt/CAPEv2/storage/binaries/f576439257053dc74512cd9ea736fd0c45ac8114beeb34410056c3adc219edc2
crc32: 48963894
md5: 25afc210a36230da71999d875c06bd37
sha1: 371994ef0e96b60c1165c7ae8854b5073b136cbc
sha256: f576439257053dc74512cd9ea736fd0c45ac8114beeb34410056c3adc219edc2
sha512: 947e2429008afb98eec51e28c3b526e4c337b8642aa4ff31a691da8b13e2c7032f93e3377c84e09d759bd562412d5600b6b349e4fdd9953f7fa7df424813066f
ssdeep: 384:r1qmFrd/ArZbwJobj0MB52hP9uNJa/jdk81byLi5hN8N9G:r1qmrtArZkLMB52hPkNgXwq8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CF923A83FF950EF2DBAA06383432997ACABDBB701D6299176785550E09362C1FC3452F
sha3_384: 758c4de37a6e3367a67d236eb9f16ce2712c9cde11aada8003f67df23384ec70ae5ad8fdd34c8d3f15ebe6b1cc0e7f00
ep_bytes: e8a3020000e97afeffff558bec8b4508
timestamp: 2021-11-22 13:52:47

Version Info:

0: [No Data]

Trojan.PhonzyPMF.S18532810 also known as:

Elasticmalicious (high confidence)
CAT-QuickHealTrojan.PhonzyPMF.S18532810
McAfeeGenericRXJF-TP!25AFC210A362
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusUnwanted-Program ( 00563d631 )
K7GWUnwanted-Program ( 00563d631 )
CyrenW32/S-892e9c2a!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GameHack.EHR potentially unsafe
APEXMalicious
ClamAVWin.Malware.Ulise-9823887-0
AvastWin32:TrojanX-gen [Trj]
RisingTrojan.Generic@ML.100 (RDML:RWmc61kvgi3jJ9pT3dQKpg)
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionGenericRXJF-TP!25AFC210A362
FireEyeGeneric.mg.25afc210a36230da
JiangminTrojan.PSW.Azorult.hge
AviraHEUR/AGEN.1138509
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R358068
VBA32BScope.Trojan.Inject
MalwarebytesSpyware.SteamStealer
YandexTrojan.GenAsa!w3Rctd0NGoM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Inject3.3157!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Trojan.PhonzyPMF.S18532810?

Trojan.PhonzyPMF.S18532810 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment