Trojan

Trojan:Win32/Phonzy.A!ml removal instruction

Malware Removal

The Trojan:Win32/Phonzy.A!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.A!ml virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Trojan:Win32/Phonzy.A!ml?


File Info:

name: 299BA99658CAFAC4BEB5.mlw
path: /opt/CAPEv2/storage/binaries/a33126d4839283ba2b2112cfa3d8a8d0b8f44a53d951c70d5359b002c15add92
crc32: F8386426
md5: 299ba99658cafac4beb5da42a59bbae3
sha1: ea5dedb1157d5aa9aaf4f80f26018a8f91c1a37e
sha256: a33126d4839283ba2b2112cfa3d8a8d0b8f44a53d951c70d5359b002c15add92
sha512: 67934feecc462cd78101adc0b3c9b1b5d2e7e4ed2808d339effa9f9167605c395f7c52cb426008e17217715a83aa47a2da67f2d52682a5ae275b28919d89478f
ssdeep: 196608:/QmtWMTGcyW0aUCB1BfsT0IV++6gXzhJLMkh3IL2LH:/N3f6V+g9JbBIGH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E166F111D241842AF5E301B6847D5B6AB528BA31131160C7F3CC6D6F67FAAE27E32B53
sha3_384: 9d259a19d0c89fa14b7ed3c0efcb9cc8d71748ae7dd54c9fed526eab058398dacef8f65f91108da75c077a6704f5f93a
ep_bytes: e82ede0000e9000000006a146898a168
timestamp: 2024-01-19 08:03:58

Version Info:

Comments: https://warzsiam.in.th/
CompanyName: Codex Development Group
FileDescription: WarZSiam Launcher
FileVersion: 1.0.0.0
InternalName: WarZSiam Launcher.exe
LegalCopyright: (c) Codex Development Group. All rights reserved.
OriginalFilename: WarZSiam Launcher.exe
ProductName: WarZSiam Launcher
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04e4

Trojan:Win32/Phonzy.A!ml also known as:

BkavW32.Common.F02568D4
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.DownLoad4.15026
MicroWorld-eScanTrojan.GenericKD.71274552
FireEyeTrojan.GenericKD.71274552
SkyhighBehavesLike.Win32.Dropper.vc
McAfeeArtemis!299BA99658CA
MalwarebytesTrojan.Agent
SangforTrojan.Win32.Agent.Vpet
K7AntiVirusTrojan ( 0059eb571 )
AlibabaTrojan:Win32/Injector.b2d38e41
K7GWTrojan ( 0059eb571 )
ArcabitTrojan.Generic.D43F9038
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win64/Agent.ST
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.71274552
NANO-AntivirusTrojan.Win32.DownLoad4.khjegk
AvastWin32:MalwareX-gen [Trj]
TencentMalware.Win32.Gencirc.11bb75a0
EmsisoftTrojan.GenericKD.71274552 (B)
F-SecureTrojan.TR/Agent.yibrn
VIPRETrojan.GenericKD.71274552
SophosMal/Generic-S
GoogleDetected
AviraTR/Agent.yibrn
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftTrojan:Win32/Phonzy.A!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKD.71274552
VaristW32/ABTrojan.IQER-3350
AhnLab-V3Trojan/Win.Generic.C5576760
VBA32BScope.Trojan.Inject
ALYacTrojan.GenericKD.71274552
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0DAJ24
RisingTrojan.Generic@AI.91 (RDML:ECjHAg++Y30W6+0vS59vAQ)
IkarusTrojan.Injector
FortinetW64/Agent.ST!tr
AVGWin32:MalwareX-gen [Trj]

How to remove Trojan:Win32/Phonzy.A!ml?

Trojan:Win32/Phonzy.A!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment