Trojan

Trojan:Script/Phonzy.B!ml (file analysis)

Malware Removal

The Trojan:Script/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Script/Phonzy.B!ml virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.

How to determine Trojan:Script/Phonzy.B!ml?


File Info:

crc32: 69163AC0
md5: 514b2d2e5d32325e587c4c42d12f04a7
name: 514B2D2E5D32325E587C4C42D12F04A7.mlw
sha1: 9cf56159ac93d1ea37e5179ec570a15ec7a07252
sha256: 0be0a47407003a6e7597abb70413ae735cc5e960b40d8a974fe9a70911af4ae0
sha512: 4f349f96839fe1232abcbc0a330009ad9962080f0acb803004635fc08ab25b4b4438e2afaf3d5993d223802bb712ad004c2ef44a29f4a3a45b3cc8b5d2ea8bbb
ssdeep: 3072:S0DpemgVst0qciSU12Eu/CSWznEeNd2LcT65hQt8Cz9B0k6Xq:RpepU127CjzEexUQSq9BH6X
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2000 - 2010 Avira GmbH. All rights reserved.
InternalName: Enaktnlrhsise Dchww
FileVersion: 00.23.83.00
CompanyName: Avira GmbH
PrivateBuild:
LegalTrademarks: AntiVirxae is a registered trademark of Avira GmbH, Germany.
Comments:
ProductName: EnakTnl Hsiseld
SpecialBuild:
ProductVersion: 00.23.83.00
FileDescription: Configuration Panel
OriginalFilename: enaktnlr.exe
Translation: 0x0800 0x04b0

Trojan:Script/Phonzy.B!ml also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43009
CynetMalicious (score: 100)
ALYacSpyware.Banker.Dridex
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3033265
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
CyrenW32/Dridex.CF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKIJ
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Malware.Dridex-9850824-0
KasperskyHEUR:Trojan.Win32.Yakes.vho
BitDefenderTrojan.Agent.FFGF
NANO-AntivirusTrojan.Win32.Packed2.itsjtv
MicroWorld-eScanTrojan.Agent.FFGF
Ad-AwareTrojan.Agent.FFGF
SophosML/PE-A + Mal/EncPk-APX
BitDefenderThetaGen:NN.ZedlaF.34678.nu8@auuqY2mO
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionDrixed-FKP!514B2D2E5D32
FireEyeGeneric.mg.514b2d2e5d32325e
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Multi.qa
AviraTR/Crypt.Agent.kbhvn
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Script/Phonzy.B!ml
GDataTrojan.Agent.FFGF
AhnLab-V3Malware/Win.AGEN.R415170
McAfeeDrixed-FKP!514B2D2E5D32
MAXmalware (ai score=80)
MalwarebytesTrojan.Dridex
RisingTrojan.Dridex!1.D4AE (CLASSIC)
YandexTrojan.Kryptik!209/npwCRwc
IkarusTrojan-Banker.Dridex
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.GEWK!tr
AVGWin32:BankerX-gen [Trj]
Qihoo-360HEUR/QVM40.1.9607.Malware.Gen

How to remove Trojan:Script/Phonzy.B!ml?

Trojan:Script/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment