Trojan

Trojan:Win32/Phonzy.B!ml information

Malware Removal

The Trojan:Win32/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.B!ml virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Phonzy.B!ml?


File Info:

name: 2A4A62FECD18F5E2692A.mlw
path: /opt/CAPEv2/storage/binaries/7c733c4b93936bbe5583c47a9f7454bac9da7eac088a2bf91a3579351a612c8c
crc32: C32FAD51
md5: 2a4a62fecd18f5e2692a3c90dab416a0
sha1: c04c3a93fab3ac83452a6b759a0aa27735f1da7e
sha256: 7c733c4b93936bbe5583c47a9f7454bac9da7eac088a2bf91a3579351a612c8c
sha512: 71ae9bb1d47e94dfaf5e0c8034cbb9803b174ac2024174fb144370fa2d0790e89b00564e8f9e52104e0d072629a8030871850afa78c072a3a39a50af106213ff
ssdeep: 768:fQLUr6D3mt02dPP3lLuzZPKqERGeo8YoRn:fGUu6xdPP3lLuBZEoeo8P
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T179E2D8597E444CEBE960173DC0EBC7762A7CF040C6235B62F664A7309B737A1219B26E
sha3_384: f0db60656a5a05134db51b4de5ba5224dbc0cfa925c10a05a4f06d2844f56e789b066555346544b8f6c9ae705070a078
ep_bytes: 57565383ec108b5c24248b7424208b7c
timestamp: 2024-02-09 05:50:46

Version Info:

0: [No Data]

Trojan:Win32/Phonzy.B!ml also known as:

LionicTrojan.Win32.Fsysna.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.71610328
FireEyeTrojan.GenericKD.71610328
SkyhighBehavesLike.Win32.Injector.nm
McAfeeGenericRXWN-OS!2A4A62FECD18
SangforTrojan.Win32.Agent.V76s
K7AntiVirusTrojan ( 005b1a3e1 )
AlibabaTrojan:Win32/Fsysna.37224e8e
K7GWTrojan ( 005b1a3e1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZedlaF.36744.c46@a8CTPed
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.DDU
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Fsysna.jgcf
BitDefenderTrojan.GenericKD.71610328
AvastWin32:MalwareX-gen [Trj]
TencentWin32.Trojan.Fsysna.Ztjl
SophosMal/Generic-S
F-SecureTrojan.TR/Dropper.Gen
EmsisoftTrojan.GenericKD.71610328 (B)
IkarusTrojan.Win32.Agent
GDataTrojan.GenericKD.71610328
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Fsysna
ArcabitTrojan.Generic.D444AFD8
ZoneAlarmTrojan.Win32.Fsysna.jgcf
MicrosoftTrojan:Win32/Phonzy.B!ml
AhnLab-V3Trojan/Win.Generic.R634466
MAXmalware (ai score=84)
Cylanceunsafe
PandaTrj/Chgt.AD
RisingTrojan.Agent!8.B1E (CLOUD)
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Phonzy.B!ml?

Trojan:Win32/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment