Trojan

How to remove “Trojan:Win32/Phonzy.B!ml”?

Malware Removal

The Trojan:Win32/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.B!ml virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Phonzy.B!ml?


File Info:

name: 64F2AB794216A7CE21CF.mlw
path: /opt/CAPEv2/storage/binaries/b7799c06636ce38e23e8870d1dbb9eb24429f5496fabade08004e9173aac4ffc
crc32: ADB6E0B2
md5: 64f2ab794216a7ce21cf7717b1577cba
sha1: 550bcd45993c05b1cf83b562c441b29096d3d4be
sha256: b7799c06636ce38e23e8870d1dbb9eb24429f5496fabade08004e9173aac4ffc
sha512: 155841f1b455d3e0898e37db7f06e9091e1cc0286c44112b31ca4bd1f4f114c7b8fa5708314548e9293dfc848acd24fffd2b3e399ae82afbfd5e54c9968224a2
ssdeep: 1536:n9QHwtRF9ESWu0SWutlggalggA3X4lhkbw3Mtr0sVxfw2JRS3:nIyRF9ESWu0SWuDmSXrw3Mtr0sC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A3A37B22A610F047E61247F0A8A73770BCF87CAA7FD5EDC29386C8567AA187955436C3
sha3_384: 91cc4453861b4a5fdcfbedd4f1daa2db5b89c7ba9711adffd56bc46d10587ec412c579fe340396f1ab0de97e24ed4580
ep_bytes:
timestamp: 2014-04-29 18:27:40

Version Info:

0: [No Data]

Trojan:Win32/Phonzy.B!ml also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
SkyhighBehavesLike.Win32.Generic.cm
McAfeeGenericRXTK-BY!64F2AB794216
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
ClamAVWin.Malware.Shodi-10014025-0
AvastWin64:Evo-gen [Trj]
RisingTrojan.Generic@AI.100 (RDML:T+6kyDy2V3SThgTalDwXHA)
IkarusTrojan.Crypt
GoogleDetected
VaristW32/S-5a8d2096!Eldorado
Antiy-AVLVirus/Win64.Shohdi.a
XcitiumHeur.Corrupt.PE@1z141z3
MicrosoftTrojan:Win32/Phonzy.B!ml
TrendMicro-HouseCallTROJ_GEN.R03BH06B624
SentinelOneStatic AI – Malicious PE
FortinetW32/Shohdi.6145!tr
AVGWin64:Evo-gen [Trj]

How to remove Trojan:Win32/Phonzy.B!ml?

Trojan:Win32/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment