Trojan

About “Trojan:Win32/Phonzy.B!ml” infection

Malware Removal

The Trojan:Win32/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.B!ml virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Trojan:Win32/Phonzy.B!ml?


File Info:

name: 41E9ABE76E961BAD6E39.mlw
path: /opt/CAPEv2/storage/binaries/19187901d82d30993d5d904430813e5e51d73f49f496e3d6d5ff0b7764e2aca6
crc32: 69307AA6
md5: 41e9abe76e961bad6e3908537c13d932
sha1: 0eed4bef7181e3a86f004a4fc7e597e4118ebb28
sha256: 19187901d82d30993d5d904430813e5e51d73f49f496e3d6d5ff0b7764e2aca6
sha512: 9496e99ee07b86ab8db5cdd2021abbf16d681923833de22cf0c4e28e16c40906b727733a3a2ec55b95fe0417103d86cd0c8c49c167171564f2bab0a7f654372c
ssdeep: 192:NVbgkRvwCeltxY+FnHS1+/u+phjInaqDE045HQKkkk:NVJRvw31YynHNu+phI9DE045H1kkk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1770319BB121C4CD1F6DC1937B2F4C1AFA7D9BA5320585704981FE99C2E693870A3B71A
sha3_384: d7714eaa8f00f1e0dfbfa63d91002abbd552ae1d3b84d39efd54fdf385abf19b22ddd5294b2d85973876c174ac6b42fb
ep_bytes: 2783a8ad63e2071e9c7dca99650c6dfb
timestamp: 2007-07-24 01:52:49

Version Info:

0: [No Data]

Trojan:Win32/Phonzy.B!ml also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Zusy.465768
FireEyeGeneric.mg.41e9abe76e961bad
SkyhighBehavesLike.Win32.Generic.pz
McAfeeArtemis!41E9ABE76E96
Cylanceunsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Generic.178b6b0f
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
ArcabitTrojan.Zusy.D71B68
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.CQD
CynetMalicious (score: 100)
APEXMalicious
BitDefenderGen:Variant.Zusy.465768
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Patched.kd
EmsisoftGen:Variant.Zusy.465768 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
VIPREGen:Variant.Zusy.465768
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
VaristW32/S-9bdefeb6!Eldorado
AviraTR/Patched.Ren.Gen
KingsoftWin32.Troj.Unknown.a
MicrosoftTrojan:Win32/Phonzy.B!ml
GDataGen:Variant.Zusy.465768
GoogleDetected
Acronissuspicious
BitDefenderThetaGen:NN.ZexaE.36680.cmY@aihbphl
ALYacGen:Variant.Zusy.465768
MAXmalware (ai score=82)
MalwarebytesMachineLearning/Anomalous.97%
TrendMicro-HouseCallTROJ_GEN.R03BH0CAO24
RisingTrojan.Generic@AI.100 (RDML:EOAybfBErOWrWHNubBvZKQ)
IkarusTrojan.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.C40A!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.f7181e
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Phonzy.B!ml?

Trojan:Win32/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment