Trojan

Trojan:Win32/Phonzy.A!ml removal

Malware Removal

The Trojan:Win32/Phonzy.A!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.A!ml virus can do?

  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Uses XCOPY for copying files

How to determine Trojan:Win32/Phonzy.A!ml?


File Info:

name: 5235005624F0396A173C.mlw
path: /opt/CAPEv2/storage/binaries/8e780b28fcffaf01c878b6a1e7fe4233acf86765f1f928705a0786bb7d248814
crc32: 1317B759
md5: 5235005624f0396a173c20032620ca4a
sha1: 9b3358d88a13e90ebb5e0a62d64c9d77220a55e4
sha256: 8e780b28fcffaf01c878b6a1e7fe4233acf86765f1f928705a0786bb7d248814
sha512: 76193194a0a1f94f4586fac600b0a0b9383487909dcd9e3935a1f59c16de6a6edbaf1982675dcfb02542d0d67d3d0730186f232164ecb3bd3b4a6410eaa6944f
ssdeep: 1536:D7fbN3eEDhDPA/pICdUkbBtW7upvaLU0bI5taxKo0IOlnToIfiw4OO:f7DhdC6kzWypvaQ0FxyNTBfiD
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T135936D41F3E242F7EAF2053100A6722F973663389764E8DBC75C2D529913AD1A63D3E9
sha3_384: 3f4c4dce1cc33274eafa5e956d1f6b45ab6d56eb7e876f93c968e5602cb3e570c7709ae135cea7b0b1c0b76baebcae64
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2019-07-30 08:52:45

Version Info:

0: [No Data]

Trojan:Win32/Phonzy.A!ml also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
ClamAVWin.Trojan.Generic-10011119-0
FireEyeGeneric.mg.5235005624f0396a
CAT-QuickHealPUA.CryptinjectPMF.S17540954
SkyhighBehavesLike.Win32.Generic.mh
SangforTrojan.Win32.Save.a
Cybereasonmalicious.88a13e
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
RisingTrojan.Undefined!8.1327C (RDMK:cmRtazpruTmkyo57bn/mlPs0lWPg)
SophosGeneric ML PUA (PUA)
GDataWin32.Trojan.PSE.72RNY9
GoogleDetected
MicrosoftTrojan:Win32/Phonzy.A!ml
VaristW32/Agent.EOE.gen!Eldorado
MalwarebytesGeneric.Malware.AI.DDS
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.216064600.susgen
FortinetW32/Nitol.AB!tr
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Phonzy.A!ml?

Trojan:Win32/Phonzy.A!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment