Trojan

What is “Trojan:Win32/Phonzy.B!ml”?

Malware Removal

The Trojan:Win32/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.B!ml virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Phonzy.B!ml?


File Info:

name: D9118069459D60E5DD64.mlw
path: /opt/CAPEv2/storage/binaries/18502c591ad2db97196f5e6e8f438657ad3dabc40cce7cdd559d8b04df22c727
crc32: C8E26CF8
md5: d9118069459d60e5dd646216d26ab058
sha1: 78818e70a73be1425e45361054847452b70be9f4
sha256: 18502c591ad2db97196f5e6e8f438657ad3dabc40cce7cdd559d8b04df22c727
sha512: f121f2b16a92ebf0a64090640dcb96e85ef41301c202fd2b9e5c30c961f11d9c1c724f9942201082414b96dd9444d545cdf0903e19bc011847bd026aa866512a
ssdeep: 98304:wMbnsqA8bPk5HyUN8k5h/wDdEoNiV4I/hwAf1wAoTamiyMXGz3atRTqk4eurBKO:Xb3bPk5HyC8k5h/wDdEoNiV4I/WWwA7M
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T195365B45E5C340F5EEA38574A297F3AFA731B5428020DDEAF9485A42EF33A51492F32D
sha3_384: da5e3c32d0233fc3db4f94e3bae110b721065a70b333c2f43eefaf758c0cee63afc46f9fa5053164fa9ecbe0718ea3bb
ep_bytes: 6a706820144000e8f701000033db538b
timestamp: 2004-08-04 06:02:34

Version Info:

CompanyName: Microsoft Corporation
FileDescription: CTF Loader
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
InternalName: CTFMON
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: CTFMON.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.1.2600.2180
OleSelfRegister:
Translation: 0x0409 0x04b0

Trojan:Win32/Phonzy.B!ml also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.69661416
ClamAVWin.Malware.Generic-9839999-0
CAT-QuickHealTrojan.AgenFC.S20327787
SkyhighBehavesLike.Win32.RealProtect.rh
McAfeeArtemis!F5726AFC419E
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDropper.Agent.Win32.468198
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005982a91 )
K7GWTrojan ( 005982a91 )
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.FIF
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Agentb.gen
BitDefenderTrojan.GenericKD.69661416
NANO-AntivirusTrojan.Win32.Dropper.kcpvrp
AvastWin32:DropperX-gen [Drp]
TencentTrojan-Dropper.MSIL.Agent.kc
EmsisoftTrojan.GenericKD.69661416 (B)
F-SecureHeuristic.HEUR/AGEN.1306700
VIPRETrojan.GenericKD.69661416
SophosTroj/Drop-DEI
IkarusTrojan-Dropper.MSIL.Agent
AviraHEUR/AGEN.1306700
Antiy-AVLTrojan/Win32.Generic
MicrosoftTrojan:Win32/Phonzy.B!ml
ArcabitTrojan.Generic.D426F2E8 [many]
ZoneAlarmHEUR:Trojan.Win32.Agentb.gen
GDataWin32.Trojan.PSE.1JZ3HIF
VaristW32/Olext.C.gen!Eldorado
VBA32TScope.Trojan.MSIL
ALYacTrojan.GenericKD.69661416
Cylanceunsafe
PandaTrj/CI.A
YandexTrojan.Agent!AXRJ9YG7c6c
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/SPNR.15EG12!tr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Phonzy.B!ml?

Trojan:Win32/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment