Trojan

Trojan:Win32/Phonzy.A!ml information

Malware Removal

The Trojan:Win32/Phonzy.A!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.A!ml virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Phonzy.A!ml?


File Info:

name: C80A2316625801E23A6F.mlw
path: /opt/CAPEv2/storage/binaries/2812c96a8111c441d3c2d484a4de59e9d6c3ac9ccd50cb15aa1d297cbb57b8f6
crc32: 37410611
md5: c80a2316625801e23a6f96201930139a
sha1: e1c46054997a4218dc0b8d0fe2321067b1fc2292
sha256: 2812c96a8111c441d3c2d484a4de59e9d6c3ac9ccd50cb15aa1d297cbb57b8f6
sha512: dd22837fd33b87f2f8d28514466ac5695b0f1422937ffe77c561d0ce30fede63e176e92f7f80280952bae0a5ac3e644169e0e1d9ceee5031fcd860c4056eb6cc
ssdeep: 12288:uLiwAwYy18yELMrv8vulB98x1adW9Y9tX6qfYHhJhtUb3Dc/uCDGdRirBqq:uLiwAwYvLMrv8vulB98x1a09m6qfsTt1
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T114F47C107580C037E663213319A9F7B999EDB8304B9516DBB3D81BBE9F786C05B3624B
sha3_384: cd86b1c143892e3913be355f8c7e1951aebbf17c775f80b5017d3cafefe5cf9b655f16892c41532fb0b197409599e664
ep_bytes: e8de110000e929feffff8b4df464890d
timestamp: 2023-11-01 13:53:00

Version Info:

FileVersion: 2.0.0.1
LegalCopyright: 2022-2023 All rights reserved
Translation: 0x0409 0x04b0

Trojan:Win32/Phonzy.A!ml also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Lazy.426915
ClamAVWin.Malware.Midie-9947458-0
CAT-QuickHealTrojan.Phonzy
SkyhighBehavesLike.Win32.Generic.bh
McAfeeGenericRXWM-CV!C80A23166258
Cylanceunsafe
ZillyaTrojan.Agent.Win32.3787899
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005adb7a1 )
AlibabaTrojan:Win32/Generic.42fc3158
K7GWTrojan ( 005adb7a1 )
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.AFZQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Backdoor.Win32.Convagent.gen
BitDefenderGen:Variant.Lazy.426915
AvastWin32:PWSX-gen [Trj]
RisingTrojan.Agent!8.B1E (TFE:1:dzXmzaXH7GT)
EmsisoftGen:Variant.Lazy.426915 (B)
F-SecureHeuristic.HEUR/AGEN.1307871
VIPREGen:Variant.Lazy.426915
TrendMicroTROJ_GEN.R002C0PLD23
SophosMal/Generic-S
GDataGen:Variant.Lazy.426915
AviraHEUR/AGEN.1307871
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Lazy.D683A3
ZoneAlarmVHO:Backdoor.Win32.Convagent.gen
MicrosoftTrojan:Win32/Phonzy.A!ml
VaristW32/S-78981dea!Eldorado
AhnLab-V3Trojan/Win.Generic.C5538172
ALYacGen:Variant.Lazy.426915
MalwarebytesMalware.AI.556498384
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PLD23
TencentMalware.Win32.Gencirc.11b9bd7e
IkarusTrojan.SuspectCRC
FortinetW32/Agent.ADKJ!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan:Win32/Phonzy.A!ml?

Trojan:Win32/Phonzy.A!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment