Trojan

How to remove “Trojan:Win32/Phonzy.B!ml”?

Malware Removal

The Trojan:Win32/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.B!ml virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Phonzy.B!ml?


File Info:

name: AEB352675C4BFBFA151C.mlw
path: /opt/CAPEv2/storage/binaries/7df543cff166b55053c234a655f163851b40135347064541675d119618fb0696
crc32: 05CAC82B
md5: aeb352675c4bfbfa151ccf9974271726
sha1: 3dcc895e4f3f5a415dd723f1da57bafb50599e0c
sha256: 7df543cff166b55053c234a655f163851b40135347064541675d119618fb0696
sha512: 0499ce2ccbd7c7d61009439d9c32420dde1e2a8ce88fb3d600bda77708cfcca842d7facb0674f47b4d1c769e451f25e9fe6d6bc57e6e797a8bcd4afa6a6f0133
ssdeep: 384:AiQILVTBc5Js3bFTpZwlfkD4mPeuaBU3losjuzZ6UwYRGZqI7PoAutqDkXHL5Rm:JVTB7rfZ2fSPP3lLuzZPKqAoPqgXr5Rm
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T181E2C7997E448CEBE950133D80E7D7762A7CF081C6234F62F654A7309E337A5609B26E
sha3_384: ad46e4b7f8722de4e1ae130edd1a5d5ed3432282dd56346afebd2e9d01dd53d8472c776d4fd9db9746e805be96d2dddc
ep_bytes: 57565383ec108b5c24248b7424208b7c
timestamp: 2024-02-09 12:17:48

Version Info:

0: [No Data]

Trojan:Win32/Phonzy.B!ml also known as:

MicroWorld-eScanGen:Variant.Babar.436367
FireEyeGen:Variant.Babar.436367
SkyhighBehavesLike.Win32.Injector.nm
McAfeeGenericRXWN-OO!AEB352675C4B
SangforTrojan.Win32.Agent.Vvac
BitDefenderThetaGen:NN.ZedlaF.36744.c46@aeNU6Yh
ESET-NOD32a variant of Win32/Agent_AGen.DDZ
BitDefenderGen:Variant.Babar.436367
ArcabitTrojan.Babar.D6A88F
MicrosoftTrojan:Win32/Phonzy.B!ml
MAXmalware (ai score=80)
DeepInstinctMALICIOUS
Cylanceunsafe
FortinetW32/Agent.DDP!tr

How to remove Trojan:Win32/Phonzy.B!ml?

Trojan:Win32/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment