Trojan

What is “Trojan:Win32/Phonzy.A!ml”?

Malware Removal

The Trojan:Win32/Phonzy.A!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.A!ml virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan:Win32/Phonzy.A!ml?


File Info:

name: 5B5C34FEEC14B1A867A3.mlw
path: /opt/CAPEv2/storage/binaries/b207b6f159f8e942c539fed3a12cc411fcd619b25404f9a59d868acebb690099
crc32: C8F60AB4
md5: 5b5c34feec14b1a867a33de6557fb6a0
sha1: 3a6e52b682753a0716f716dc29e58386713f9290
sha256: b207b6f159f8e942c539fed3a12cc411fcd619b25404f9a59d868acebb690099
sha512: 75f29cc648091e36f2e19bcbb87ee10366d957cbec27d79f77cdb45fe72ace52fe6db86579f3ca9eef9f0deb325ff531b1999e95d29fc1daccf7ac6e427480cd
ssdeep: 768:4rjWydZNHVzXq6aFMl2wQAYvZHrjWydZNHVzXO6aFMl2wQAYvZ:4rjWXMloHrjW/Mlo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T137644A97FE51C6B2D8228EFC0C578119A6E33B303E7804C5BA9A9FCEA97D5D11A0D446
sha3_384: 32b342a16d258fc296bc7f3c0fd78aaa0f7a33ba5ff6ddcbac9329d95d4ab3006cf3e1ad13a1ef6efb9b9a72ef5578ef
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan:Win32/Phonzy.A!ml also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Lamer.kYNN
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Kazaa.924
MicroWorld-eScanTrojan.Agent.EICV
FireEyeGeneric.mg.5b5c34feec14b1a8
SkyhighGenericRXUX-FE!5B5C34FEEC14
McAfeeGenericRXUX-FE!5B5C34FEEC14
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusUnwanted-Program ( 0059886f1 )
AlibabaWorm:Win32/Xolxo.45b
K7GWUnwanted-Program ( 0059886f1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Delf.NAY
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Delf-6737076-0
BitDefenderTrojan.Agent.EICV
NANO-AntivirusTrojan.Win32.Kazaa.kfxxhi
AvastWin32:Delf-SVI [Trj]
TencentVirus.Win32.Lamer.fh
EmsisoftTrojan.Agent.EICV (B)
VIPRETrojan.Agent.EICV
TrendMicroMal_Krap-8
SophosMal/Generic-S
IkarusTrojan.Agent
JiangminTrojan.Agent.dqxf
VaristW32/Agent.DMD.gen!Eldorado
Kingsoftmalware.kb.b.964
MicrosoftTrojan:Win32/Phonzy.A!ml
XcitiumHeur.Corrupt.PE@1z141z3
ArcabitTrojan.Agent.EICV
GDataTrojan.Agent.EICV
GoogleDetected
VBA32Worm.Delf
ALYacTrojan.Agent.EICV
MAXmalware (ai score=85)
MalwarebytesGeneric.Trojan.Delf.DDS
TrendMicro-HouseCallMal_Krap-8
RisingVirus.BagarBubba!1.D52A (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Delf.NAY
AVGWin32:Delf-SVI [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Phonzy.A!ml?

Trojan:Win32/Phonzy.A!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment