Trojan

Trojan:Win32/Phonzy.A!ml removal instruction

Malware Removal

The Trojan:Win32/Phonzy.A!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.A!ml virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Phonzy.A!ml?


File Info:

name: B0FEBE4EB16991698387.mlw
path: /opt/CAPEv2/storage/binaries/0e41902c22a1a784fb997dd548cd166327d52901188382c89752bf2d029c7b5d
crc32: 48FAEA82
md5: b0febe4eb169916983876843e29b0d32
sha1: fc83a6a111c44a7480d2b0d1d7601abdd92ebf7b
sha256: 0e41902c22a1a784fb997dd548cd166327d52901188382c89752bf2d029c7b5d
sha512: 121305c6abb24203b132e6128f773f07b95dabf785879d20eb39bb11afcc09a8c3ae5f37a300b423a7f712aeb0dc3d83f625712707765d971b43bcf0316ea59a
ssdeep: 12288:kSbbRWutBQwaqdXiXi/cI0dG508RUi5tiE5IDAVRAdFmExWGmu4fO/SMZoS8sEw0:BTZaqdiXSp0c02uFG6dAk3CMmwkj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10D152311921117C7E4970BB648F339850CE4F1B6A661A63B0F482CFE3D5BE59DAA81CF
sha3_384: 589981745e3e5b2161ae3c7d6730ffdec3483028876011952cf3a45ed998e229f6702b519ad33a1b16eb6baf29631d29
ep_bytes: e80600000050e8bb010000558bec81c4
timestamp: 1972-12-25 05:33:23

Version Info:

FileVersion: 1.0.0.0
FileDescription: 老锋专用 QQ1353618144
ProductName: 老锋专用 QQ1353618144
ProductVersion: 1.0.0.0
CompanyName: 老锋
LegalCopyright: 老锋 版权所有
Comments: 老锋专用 QQ1353618144
Translation: 0x0804 0x04b0

Trojan:Win32/Phonzy.A!ml also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Flystudio-9943951-0
FireEyeGeneric.mg.b0febe4eb1699169
SkyhighBehavesLike.Win32.RealProtect.cc
Cylanceunsafe
K7AntiVirusTrojan ( 005194cc1 )
K7GWTrojan ( 005194cc1 )
CrowdStrikewin/grayware_confidence_60% (W)
VirITTrojan.Win32.Generic.CDXU
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
AvastWin32:Malware-gen
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
IkarusTrojan.Backdoor.FlyAgent
Webroot
GoogleDetected
Antiy-AVLTrojan/Win32.Wacatac.b
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.FlyStudio.~UJ@1sa9s6
MicrosoftTrojan:Win32/Phonzy.A!ml
GDataWin32.Riskware.FlyStudio.C
VaristW32/S-759a1e41!Eldorado
McAfeeArtemis!B0FEBE4EB169
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R002H0CJI23
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.Flystudio.Y
FortinetW32/FlyStudio.C!tr
AVGWin32:Malware-gen
Cybereasonmalicious.111c44
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Phonzy.A!ml?

Trojan:Win32/Phonzy.A!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment