Trojan

Trojan:Win32/Phonzy.B!ml (file analysis)

Malware Removal

The Trojan:Win32/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.B!ml virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Trojan:Win32/Phonzy.B!ml?


File Info:

name: 35730631CFA8E29A4525.mlw
path: /opt/CAPEv2/storage/binaries/faf48bb1c2215c27a0239a9f3bae0d6d2721f65ed87e849ec145a6905e87dcd9
crc32: 7F62D13E
md5: 35730631cfa8e29a45252e8f1f4a7983
sha1: 6e73f6aec64e02dc7d885f3f68038b5e9e8c4262
sha256: faf48bb1c2215c27a0239a9f3bae0d6d2721f65ed87e849ec145a6905e87dcd9
sha512: df5c3e7827a11a791d24af168f3d98e501d157083043e674daf982c48c16cce8865319a7d246f58ba8224b08ba8f8961fbcba0815bfeb8e54674e20e0f4d0234
ssdeep: 192:lsah2DB0by8KwIj6O0LPFE9easJ9/m04/7nkn3Xc8XY1mumzrqDE045HQvQQQ:6DObKwFrCeh9rFc4Y5DE045H2QQQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T119039D32D6DC86E8FF5D8AF3072E02DB4FDA356049A4902C4A4EFB4C1F9654C1A45B17
sha3_384: f6be63f339f169d30f9b22a405514a95385261e88e35b66676d2dbd865cdd8b8a103bfc7afa829b284361f5805cbd04f
ep_bytes: ee9fe80b64d7d44e4fe464391f27f9bb
timestamp: 2007-07-24 01:52:49

Version Info:

0: [No Data]

Trojan:Win32/Phonzy.B!ml also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.173465
FireEyeGeneric.mg.35730631cfa8e29a
SkyhighBehavesLike.Win32.Generic.pz
McAfeeArtemis!35730631CFA8
Cylanceunsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Generic.ef0872a7
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaE.36680.cmY@aihbphl
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.CQD
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Cerbu.173465
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Patched.kd
EmsisoftGen:Variant.Cerbu.173465 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
VIPREGen:Variant.Cerbu.173465
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Cerbu.173465
VaristW32/S-9bdefeb6!Eldorado
AviraTR/Patched.Ren.Gen
Kingsoftmalware.kb.a.1000
ArcabitTrojan.Cerbu.D2A599
MicrosoftTrojan:Win32/Phonzy.B!ml
GoogleDetected
Acronissuspicious
ALYacGen:Variant.Cerbu.173465
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R03BH0CAV24
RisingTrojan.Generic@AI.100 (RDML:lyMH+ty51VNnkQrJD/4+JQ)
IkarusTrojan.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.C40A!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.ec64e0
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Phonzy.B!ml?

Trojan:Win32/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment