Trojan

Trojan:Win32/Phonzy.B!ml removal instruction

Malware Removal

The Trojan:Win32/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.B!ml virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid

How to determine Trojan:Win32/Phonzy.B!ml?


File Info:

name: 7127424C03598E778EA9.mlw
path: /opt/CAPEv2/storage/binaries/b35f6527e56b60953321fc79995fa1a5f9f49ac0bba0b4c26174b5ff75d6af68
crc32: F27304A9
md5: 7127424c03598e778ea9aa05f76b8512
sha1: d4fc98283af10cf1b2bd5d2cddf1677643cca57c
sha256: b35f6527e56b60953321fc79995fa1a5f9f49ac0bba0b4c26174b5ff75d6af68
sha512: 853ca7b883137d4bdeb239c7b0c1b2e512370565a0a19459b76e3a7d82752e513ea9e898edc447bb533fc32a53f3430cc42c16288bbe0b588900b00841786bb5
ssdeep: 3072:yaVMfMIbIaw3J9UG2NFfngVN+BC3K5eqU+BC3K5eqYroGZVhlb4:yffMmM72NFfgV/K70K7U
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A2F3AE01F3C0DE67E468253184A747630A7DBD25E66262AB17883F6FDDB02605A37F1B
sha3_384: 8e2943c06a98144e192666e3581c27408c0c3d1b7227434445a29a6f5aa66f14fa2ac870810d454467386ca728faec3f
ep_bytes: ecfbffdbf0fcff6f7477fa7290a1ff9f
timestamp: 2013-05-05 11:53:34

Version Info:

0: [No Data]

Trojan:Win32/Phonzy.B!ml also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Gepys.4!c
DrWebTrojan.Mods.146
MicroWorld-eScanGen:Variant.Fragtor.348825
FireEyeGeneric.mg.7127424c03598e77
SkyhighBehavesLike.Win32.Ursnif.cm
ALYacGen:Variant.Fragtor.348825
MalwarebytesCrypt.Trojan.Malicious.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
AlibabaTrojanDropper:Win32/Mods.c3dc8091
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.83af10
ArcabitTrojan.Fragtor.D55299
BitDefenderThetaGen:NN.ZexaF.36792.kmZ@aKensxm
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Gepys-9770177-0
BitDefenderGen:Variant.Fragtor.348825
AvastWin32:Gepys-B [Trj]
SophosMal/Generic-S
F-SecureTrojan.TR/Patched.Ren.Gen
BaiduWin32.Trojan.Injector.jn
VIPREGen:Variant.Fragtor.348825
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Fragtor.348825 (B)
SentinelOneStatic AI – Malicious PE
VaristW32/S-c8e04512!Eldorado
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Wacatac
Kingsoftmalware.kb.b.998
MicrosoftTrojan:Win32/Phonzy.B!ml
GDataWin32.Trojan.PSE.4GH6H3
GoogleDetected
Acronissuspicious
McAfeeArtemis!7127424C0359
TACHYONTrojan/W32.Agent.167936.CFJ
VBA32Trojan.Redirect
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R03BH09KO23
RisingTrojan.Kryptik!1.BC3A (CLASSIC)
IkarusTrojan.Win32.Revoyem
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/PossibleThreat
AVGWin32:Gepys-B [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Phonzy.B!ml?

Trojan:Win32/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment