Trojan

Should I remove “Trojan:Win32/Phonzy.B!ml”?

Malware Removal

The Trojan:Win32/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.B!ml virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Phonzy.B!ml?


File Info:

name: B8D2453CA917EF8B29D3.mlw
path: /opt/CAPEv2/storage/binaries/fd605de712a50f75ed2af296101bd20c5e667eb7e84d6c5ae83b002f1f4aa8f8
crc32: B6EF882C
md5: b8d2453ca917ef8b29d30780c7549b4e
sha1: 1e59e5bf059828742ef82a228bdc1c7fe88a2b7b
sha256: fd605de712a50f75ed2af296101bd20c5e667eb7e84d6c5ae83b002f1f4aa8f8
sha512: 7055e427218567353be017710383d954f5fc7ffffaa8e1267380e7c7089eee0db52553bc904d05bf5261e96ae426b8ccae99d5c826ab3b5fdf5f5697cd5e3a25
ssdeep: 384:d207T0fjnnfOKZwl2QCmPeuaBU3losjuzZ6UwYRGZqc7PA/ScIDctHJ3Rn:j7ornnpZ224PP3lLuzZPKq04IYtp3Rn
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T19AE2D6597E448CEBE950273984E7C7762B3CF181C6234B62F610A7309F637A1619B26F
sha3_384: 463fab4022675fde4d054ed236f0934ad64d7e9f37d9bd17d2a88d2fc0dd832e5d3dadc6fff3bcf99ee29e354d5eb08f
ep_bytes: 57565383ec108b5c24248b7424208b7c
timestamp: 2024-02-09 05:54:19

Version Info:

0: [No Data]

Trojan:Win32/Phonzy.B!ml also known as:

MicroWorld-eScanGen:Variant.Fragtor.503441
SkyhighBehavesLike.Win32.Injector.nm
McAfeeGenericRXWN-OT!B8D2453CA917
VIPREGen:Variant.Fragtor.503441
SangforTrojan.Win32.Agent.V3c5
AlibabaTrojan:Win32/Fsysna.7a9ef439
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZedlaF.36744.b46@ayAkWBf
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.DDZ
KasperskyTrojan.Win32.Fsysna.jgfu
BitDefenderGen:Variant.Fragtor.503441
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Fsysna.Agow
EmsisoftGen:Variant.Fragtor.503441 (B)
F-SecureTrojan.TR/Agent_AGen.xgbkw
FireEyeGen:Variant.Fragtor.503441
SophosMal/Generic-S
MAXmalware (ai score=87)
GDataGen:Variant.Fragtor.503441
GoogleDetected
AviraTR/Agent_AGen.xgbkw
Antiy-AVLTrojan/Win32.Fsysna
ArcabitTrojan.Fragtor.D7AE91
ZoneAlarmTrojan.Win32.Fsysna.jgfu
MicrosoftTrojan:Win32/Phonzy.B!ml
CynetMalicious (score: 99)
AhnLab-V3Malware/Win.Generic.R634606
Cylanceunsafe
PandaTrj/Chgt.AD
RisingTrojan.Agent!8.B1E (TFE:5:LOV478XbAmT)
IkarusTrojan.Win32.Agent
FortinetW32/Agent_AGen.DDZ!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Phonzy.B!ml?

Trojan:Win32/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment