Trojan

About “Trojan:Win32/Phonzy.B!ml” infection

Malware Removal

The Trojan:Win32/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.B!ml virus can do?

  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Phonzy.B!ml?


File Info:

name: 409BB819C6F3BC1CFEE7.mlw
path: /opt/CAPEv2/storage/binaries/eccc3987116583ffd48810b89e3b0e608282191052b6aaf70fe6686c5dde6b79
crc32: 96FF2674
md5: 409bb819c6f3bc1cfee76bc32147cc8c
sha1: 5985e3c0c72d287b24ffdd57b7f0781d1b7cf152
sha256: eccc3987116583ffd48810b89e3b0e608282191052b6aaf70fe6686c5dde6b79
sha512: ede62ded82ddd7ce6f3e410da959f9891b11aadcbfe676e5f28c11105a1d9eec6d55f7d86c82490fc24316392230ff1224ced6ef296e9c1c3561d890cab8afdc
ssdeep: 196608:6b3bPk5HyC8k5h/wDdEoNiV4I/WWwA7mdep7:6b3bPk5HPhJCde
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17C666B01E6C340B4EEA34174929BF36FA735B58183249CEBF5885A85EF33AD1593E319
sha3_384: 5ce52f556e7210a53c01279855fb71794f5777d8004e23a2c891d6c0b47033e7437918a2c84bd89f30ca37ea1b37a513
ep_bytes: ff250020400000000000000000000000
timestamp: 2007-10-24 03:31:10

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft .NET Assembly Registration Utility
FileVersion: 2.0.50727.1433 (REDBITS.050727-1400)
InternalName: RegAsm.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: RegAsm.exe
ProductName: Microsoft® .NET Framework
ProductVersion: 2.0.50727.1433
Comments: Flavor=Retail
Translation: 0x0409 0x04b0

Trojan:Win32/Phonzy.B!ml also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.321815
FireEyeGeneric.mg.409bb819c6f3bc1c
CAT-QuickHealTrojan.AgenFC.S20327787
SkyhighBehavesLike.Win32.Generic.vh
McAfeeArtemis!409BB819C6F3
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005982511 )
K7GWTrojan ( 005982511 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Lazy.D4E917
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.FIF
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Generic-9839999-0
BitDefenderGen:Variant.Lazy.321815
NANO-AntivirusTrojan.Win32.Dropper.kcpvrp
AvastWin32:DropperX-gen [Drp]
TencentTrojan-Dropper.MSIL.Agent.ka
EmsisoftGen:Variant.Lazy.321815 (B)
F-SecureHeuristic.HEUR/AGEN.1306700
VIPREGen:Variant.Lazy.321815
SophosTroj/Drop-DEI
IkarusTrojan-Dropper.MSIL.Agent
VaristW32/MSIL_Kryptik.CZ.gen!Eldorado
AviraHEUR/AGEN.1306700
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Generic
MicrosoftTrojan:Win32/Phonzy.B!ml
GDataMSIL.Trojan.PSE.1AJ2WXA
GoogleDetected
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.Lazy.321815
PandaTrj/CI.A
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/SPNR.15EG12!tr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Phonzy.B!ml?

Trojan:Win32/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment