Trojan

Trojan:Win32/Phonzy.B!ml removal

Malware Removal

The Trojan:Win32/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.B!ml virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Trojan:Win32/Phonzy.B!ml?


File Info:

name: 8D694AD12D5E651FF7BF.mlw
path: /opt/CAPEv2/storage/binaries/b101368352bffd1fc0a50ef52b8e17e3e9ed6c436417e511c6401f1c5de0a6eb
crc32: 7E7BCD5E
md5: 8d694ad12d5e651ff7bf75c54f1be098
sha1: a4c6505b084608d975b38993ba4536fca9d52061
sha256: b101368352bffd1fc0a50ef52b8e17e3e9ed6c436417e511c6401f1c5de0a6eb
sha512: 31e258db954ae22e43b2c20c06568a6b7eb43808a07e4276a7de2293c211d3e60bb0d3b4b7ff14f80706da0a746845b36afe553c7d22819bf6293bd4b8f0b216
ssdeep: 192:CnUqFJBQa3eNb+6FGHZmF5lCKCWWT9JxXNX1xV70SGFfOoH/i6oggqDE045HQP:TOLetI4Fb8J9NZ7lKflH/Xo2DE045H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15E038E712E8D44BAFF4C12FB46A70AD255EBB2B696D5842F410FD42A1E7DB946330307
sha3_384: 52fe95301092ee04d91dd89a39901a978ebe77ed946ce88013eca34838502c3cf69f4719875fc9b3c151a7680ec79749
ep_bytes: a47addc1883e711719555f060a23ea9c
timestamp: 2007-07-24 01:52:49

Version Info:

0: [No Data]

Trojan:Win32/Phonzy.B!ml also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.8d694ad12d5e651f
SkyhighBehavesLike.Win32.Generic.pz
McAfeeArtemis!8D694AD12D5E
MalwarebytesMachineLearning/Anomalous.100%
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
ArcabitTrojan.Cerbu.D2A599
BitDefenderThetaGen:NN.ZexaF.36680.cmY@aihbphl
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CQD
APEXMalicious
BitDefenderGen:Variant.Cerbu.173465
MicroWorld-eScanGen:Variant.Cerbu.173465
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Patched.kd
EmsisoftGen:Variant.Cerbu.173465 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
VIPREGen:Variant.Cerbu.173465
SophosGeneric ML PUA (PUA)
IkarusTrojan.Patched
GoogleDetected
AviraTR/Patched.Ren.Gen
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Phonzy.B!ml
GDataGen:Variant.Cerbu.173465
VaristW32/S-9bdefeb6!Eldorado
Acronissuspicious
ALYacGen:Variant.Cerbu.173465
MAXmalware (ai score=88)
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BH0CAQ24
RisingTrojan.Generic@AI.100 (RDML:zaHyUQwf6cXcK6G7KOP0VQ)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.C40A!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.b08460
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Phonzy.B!ml?

Trojan:Win32/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment