Trojan

Should I remove “Trojan:Win32/Phonzy.B!ml”?

Malware Removal

The Trojan:Win32/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.B!ml virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Phonzy.B!ml?


File Info:

name: 645C0C3D0E8510FA9423.mlw
path: /opt/CAPEv2/storage/binaries/e4802f4a9fc97fdb6f603a780cfeae37ac89a35865c6aae804a52e6a6ab5d01c
crc32: 11134CFE
md5: 645c0c3d0e8510fa9423e2627df5dcc9
sha1: d41ea40d2f639ad68ae6b19dd7439401ce385e95
sha256: e4802f4a9fc97fdb6f603a780cfeae37ac89a35865c6aae804a52e6a6ab5d01c
sha512: d4e781903d6bc72edcb6b961fe4d7f6bb48d11a7c14c553e91394a5df55ca112c89e8ea960f7d64a58508b62a7f49c637ae04f9232a03cb38eba3099d4beffe0
ssdeep: 3072:rrcDFxUcrRmqz0HJ+jfvyKUjFUo0RvfMeFPm8m9hbMvS1Lq9hiIiU0WqqVikSiDr:rruz0UUjFsRvk8mR9B51UhiI2WqqVikr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T105F3024A7AC1D87BDA234B710D398FDBA3B5D30101794317FB608E88BD2279B4E86243
sha3_384: 7d855febaffe36186f4762887570005a7cf187990954a6e02684020c3f0fc841653660694053ac948a83bdd5b884ac4f
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2014-03-22 07:23:01

Version Info:

CompanyName: 快屏网络科技有限公司
FileDescription: 斑马日历安装程序
FileVersion: V1.0
InternalName: $Name
LegalCopyright: Copyright (C) 2014快屏网络
LegalTrademarks: 快屏网络
ProductName: 斑马日历
ProductVersion: 1.0.0.0
Translation: 0x0804 0x03a8

Trojan:Win32/Phonzy.B!ml also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.Generic.3606331
CAT-QuickHealTrojan.MauvaiseRI.S5245166
SkyhighBehavesLike.Win32.Trojan.cc
MalwarebytesPUP.Optional.ChinAd.DDS
VIPREApplication.Generic.3606331
SangforTrojan.Win32.Save.a
BitDefenderApplication.Generic.3606331
VirITTrojan.Win32.KillFiles.BQFE
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.NSISmod.A suspicious
ClamAVWin.Trojan.15173305-1
Kasperskynot-a-virus:HEUR:AdWare.NSIS.Xpyn.heur
NANO-AntivirusTrojan.Win32.Pincav.dtlemb
TencentBackdoor.Win32.Poison.pb
EmsisoftApplication.Generic.3606331 (B)
DrWebTrojan.KillFiles.28526
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.645c0c3d0e8510fa
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Pincav
MAXmalware (ai score=78)
GDataApplication.Generic.3606331
GoogleDetected
VaristW32/Xpyn.A.gen!Eldorado
Antiy-AVLGrayWare[AdWare]/Win32.PackedNsisMod.a
Kingsoftmalware.kb.a.857
ArcabitApplication.Generic.D37073B
ZoneAlarmnot-a-virus:HEUR:AdWare.NSIS.Xpyn.heur
MicrosoftTrojan:Win32/Phonzy.B!ml
CynetMalicious (score: 100)
VBA32Adware.NSIS.Xpyn
ALYacApplication.Generic.3606331
RisingMalware.NSISMod!1.DBC4 (CLASSIC)
YandexTrojan.GenAsa!hrZneoTQ9ng
SentinelOneStatic AI – Suspicious PE
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_90% (D)

How to remove Trojan:Win32/Phonzy.B!ml?

Trojan:Win32/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment