Trojan

About “Trojan:Win32/Phonzy.A!ml” infection

Malware Removal

The Trojan:Win32/Phonzy.A!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.A!ml virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Phonzy.A!ml?


File Info:

name: E66E0E2C9CBDC97BECC3.mlw
path: /opt/CAPEv2/storage/binaries/76868bce5caec990be54773e971e4b34789b03c9885d64dd47171e060f65e0fb
crc32: 12C3BB59
md5: e66e0e2c9cbdc97becc3723e838750e6
sha1: 2d6e521cf793d3b4d59447d0da7bc2e2966ef852
sha256: 76868bce5caec990be54773e971e4b34789b03c9885d64dd47171e060f65e0fb
sha512: dbb2805d60383d51ccfb752880065dfe0d47316fc77a449bdc5fdcbd306b75c26e771cf6c9e893f125a9d5f23d314de8e959eff889766399554e0824ed537957
ssdeep: 768:yGEhgnoeZGcJPP3lLuzZPKqUjtJY/MURi:yGEhq77JPP3lLuBZUc/e
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T176E2C6597E044DEBE951173C85E7C77A2A3CF180C6234B62F650E7309B337A6609A27E
sha3_384: e5d87f622ed002b0a2a3a0908c5c585e4c8e74b0a96177161b08b2b060208449aef0be4849193f4cd808982c33f56a94
ep_bytes: 57565383ec108b5c24248b7424208b7c
timestamp: 2024-02-09 08:21:01

Version Info:

0: [No Data]

Trojan:Win32/Phonzy.A!ml also known as:

LionicTrojan.Win32.Agent.Y!c
MicroWorld-eScanGen:Variant.Fragtor.502822
FireEyeGeneric.mg.e66e0e2c9cbdc97b
SkyhighBehavesLike.Win32.Injector.nm
McAfeeGenericRXWN-OT!E66E0E2C9CBD
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005b1a3b1 )
AlibabaTrojan:Win32/Injector.8a19aff7
K7GWTrojan ( 005b1a3b1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Fragtor.D7AC26
BitDefenderThetaGen:NN.ZedlaF.36744.c46@ayVqeNn
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.ETQB
KasperskyTrojan.Win32.Agent.xbkwgq
BitDefenderGen:Variant.Fragtor.502822
AvastWin32:MalwareX-gen [Trj]
TencentWin32.Trojan.Agent.Oqil
EmsisoftGen:Variant.Fragtor.502822 (B)
F-SecureTrojan.TR/Agent_AGen.tafdz
DrWebBACKDOOR.Trojan
VIPREGen:Variant.Fragtor.502822
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=81)
GoogleDetected
AviraTR/Agent_AGen.tafdz
VaristW32/Agent.IIE.gen!Eldorado
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftTrojan:Win32/Phonzy.A!ml
ZoneAlarmTrojan.Win32.Agent.xbkwgq
GDataGen:Variant.Fragtor.502822
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.R634642
ALYacGen:Variant.Fragtor.502822
PandaTrj/Chgt.AD
RisingTrojan.Agent!8.B1E (TFE:5:kvndo5M1JLT)
IkarusTrojan.Win32.Agent
FortinetW32/Agent.DDP!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Phonzy.A!ml?

Trojan:Win32/Phonzy.A!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment