Trojan

Trojan:Win32/Phonzy.B!ml removal tips

Malware Removal

The Trojan:Win32/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.B!ml virus can do?

  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Phonzy.B!ml?


File Info:

name: 9491EDB58C2C24AE9663.mlw
path: /opt/CAPEv2/storage/binaries/3c6c25e9e37e4213a89157e882eb589ddcdbf7ddc6340ae8a20aba7f01bd661d
crc32: 41CD58D3
md5: 9491edb58c2c24ae96635f339e5bf8e2
sha1: 3c23d260f71621c921c65dcf06cdcd6024117dc1
sha256: 3c6c25e9e37e4213a89157e882eb589ddcdbf7ddc6340ae8a20aba7f01bd661d
sha512: 8b716277b5c5ff7c9403084ce443b4bf684a5aeaee0b2c769e975ec499937b0302f03646e979a3851f1794217105b08fb7b20469d9808071eaa8ade18099d8c2
ssdeep: 24576:9vyz9lmA5/YgStROnhmQd4XDOg9KAgX4IIMd9frQ2QO3g5gDsHb:9Gug9ZdiygDC4IrVQ2Q0QgAHb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13F55BF13A54240B1D64D21311DEF2B3BEEB943B50E319A87E394DDBEBE22671D92321D
sha3_384: cee4c9ab7705c85c1d3f678779f92f6117814f06985fdd4f078c4f061a8d99020e57e016c5a4539a715bc9f2f6b66269
ep_bytes: 558bec6aff68785c520068040d490064
timestamp: 2013-04-26 09:30:58

Version Info:

FileVersion: 1.0.0.0
FileDescription: 清风
ProductName: 清风
ProductVersion: 1.0.0.0
CompanyName: 清风
LegalCopyright: 清风 版权所有
Comments: 清风
Translation: 0x0804 0x04b0

Trojan:Win32/Phonzy.B!ml also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
FireEyeGeneric.mg.9491edb58c2c24ae
SkyhighBehavesLike.Win32.Generic.th
MalwarebytesGeneric.Malware.AI.DDS
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005886601 )
Cybereasonmalicious.0f7162
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
SophosGeneric ML PUA (PUA)
F-SecureTrojan:W32/DelfInject.R
Trapminemalicious.moderate.ml.score
SentinelOneStatic AI – Malicious PE
VaristW32/Trojan.CLL.gen!Eldorado
Antiy-AVLTrojan/Win32.FlyStudio.a
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.Dropper.RA@1qraug
MicrosoftTrojan:Win32/Phonzy.B!ml
GDataWin32.Trojan.PSE.1CJUYU
GoogleDetected
BitDefenderThetaGen:NN.ZexaF.36792.sr0@a4CPYTeb
VBA32BScope.Backdoor.Farfli
Cylanceunsafe
IkarusTrojan.Win32.QQWare
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.PHP!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Trojan:Win32/Phonzy.B!ml?

Trojan:Win32/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment