Trojan

Should I remove “Trojan:Win32/Phonzy.A!ml”?

Malware Removal

The Trojan:Win32/Phonzy.A!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.A!ml virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Installs a browser addon or extension
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • Deletes executed files from disk

How to determine Trojan:Win32/Phonzy.A!ml?


File Info:

name: FD3E652D2905E46AC123.mlw
path: /opt/CAPEv2/storage/binaries/318719f0d592d22a95e1fc985a613a6317acc17973015ccb48506e333301c130
crc32: 259E1164
md5: fd3e652d2905e46ac12376c0e189d295
sha1: f7a7557c42633d57f2ba5cfede3b1d343c2e9041
sha256: 318719f0d592d22a95e1fc985a613a6317acc17973015ccb48506e333301c130
sha512: dc3ef58a45bad4d0029c9e666577ef2aca5dba4029c4bff463515caef1d24f990456e6835f61175166f249679f97aca695a8859b6f3abaf52120d82476b70eee
ssdeep: 12288:uaHc64b888888888888W88888888888DoscV7/9GqeMo3oM5omOX2n33rD+zG/os:F86qjW7/9ooTrGnezG/aYFkJR30F6rpA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15AF40213B3C30071F5665A35CCB6C044AD2778B909F0605A2EF9EB4E4EBA6C69D77B21
sha3_384: e72c1b604f1cd290fd1c9e039527acfdb30137840c808cd64c586d778aa5015816681b26dbaf12fcce6237fc985ae2e3
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2018-06-14 13:27:46

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription:
FileVersion: 165.245
LegalCopyright:
ProductName:
ProductVersion: 165.245
Translation: 0x0000 0x04b0

Trojan:Win32/Phonzy.A!ml also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Addrop.A.B4B71E40
SkyhighBehavesLike.Win32.Dropper.bc
MalwarebytesTrojan.Dropper
Cybereasonmalicious.d2905e
ESET-NOD32a variant of Win32/TrojanDropper.Addrop.CH
APEXMalicious
ClamAVWin.Malware.Ejfb-9784212-0
KasperskyTrojan.Win32.MalCrack.a
BitDefenderGeneric.Addrop.A.B4B71E40
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastNSIS:Adware-AEQ [Adw]
TencentTrojan.Win32.MalCrack.haw
EmsisoftGeneric.Addrop.A.B4B71E40 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen8
VIPREGeneric.Addrop.A.B4B71E40
FireEyeGeneric.Addrop.A.B4B71E40
SophosML/PE-A
IkarusTrojan-Dropper.Addrop
JiangminTrojanDropper.Agentino.a
WebrootW32.Adware.Gen
VaristW32/Addrop.D.gen!Eldorado
AviraTR/Crypt.XPACK.Gen8
MicrosoftTrojan:Win32/Phonzy.A!ml
ZoneAlarmTrojan.Win32.MalCrack.a
GDataGeneric.Addrop.A.B4B71E40
CynetMalicious (score: 100)
AhnLab-V3Adware/Win.Addrop.C5573689
ALYacGeneric.Addrop.A.B4B71E40
RisingDownloader.TaskLoader/ARCHIVE!1.CDEA (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Addrop.CH!tr
AVGNSIS:Adware-AEQ [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Phonzy.A!ml?

Trojan:Win32/Phonzy.A!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment