Trojan

Trojan:Win32/Phonzy.B!ml removal tips

Malware Removal

The Trojan:Win32/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.B!ml virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Phonzy.B!ml?


File Info:

name: 7D512BFCEA08C71A75DC.mlw
path: /opt/CAPEv2/storage/binaries/0c8a71e29739b1e7313603a58594c63fad4ed7af7dacfd5eee8a53778601836b
crc32: 978EE331
md5: 7d512bfcea08c71a75dce9326a7ce031
sha1: efdcf7dc5ec5ae70a7aa22e12bc7d76662bd1c7e
sha256: 0c8a71e29739b1e7313603a58594c63fad4ed7af7dacfd5eee8a53778601836b
sha512: 245498903a9582fd44b673375dd97a840a3adea4dd7f878ad072e4afe4b48e67900be4b29931ce616b8567edb3a065e3beee30cba35e8288233e48e43de0723b
ssdeep: 6144:OIs9OKofHfHTXQLzgvnzHPowYbvrjD/L7QPbg/Dr0T3rnXLHf7zjPFsEPAmofHfA:TKofHfHTXQLzgvnzHPowYbvrjD/L7QPX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E3343B1AF502D4F3DB2909B406C6F1BE5A20B924C8298F4BF781CE6ADC73DB46569713
sha3_384: 0365122e247b03842d43e78189e981f96c6725fe0b9f25255ca3a5b68fdb75c1cd22048048e0e2f1883ebdd2c2f1887a
ep_bytes: 00000000000000000000000000000000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Phonzy.B!ml also known as:

BkavW32.AIDetectMalware
FireEyeGeneric.mg.7d512bfcea08c71a
SkyhighBehavesLike.Win32.Generic.dz
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Generickdz-9918324-0
KasperskyHEUR:Email-Worm.Win32.LovGate.pef
AvastWin32:Mydoom-BJ [Wrm]
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Mydoom
VaristW32/Mydoom.G.gen!Eldorado
Antiy-AVLTrojan/Win32.Mydoom.a
XcitiumPacked.Win32.MUPX.Gen@24tbus
MicrosoftTrojan:Win32/Phonzy.B!ml
ZoneAlarmHEUR:Email-Worm.Win32.LovGate.pef
GDataWin32.Trojan.Agent.JU4X83
GoogleDetected
McAfeeGenericRXWA-TO!7D512BFCEA08
Cylanceunsafe
RisingWorm.Agent!1.C364 (CLASSIC)
YandexTrojan.AvsArher.bSFjus
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Mydoom-BJ [Wrm]
Cybereasonmalicious.c5ec5a
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Phonzy.B!ml?

Trojan:Win32/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment