Trojan

Trojan:Win32/Phonzy.B!ml malicious file

Malware Removal

The Trojan:Win32/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.B!ml virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Phonzy.B!ml?


File Info:

name: 9AC239C354ABD23CF3C0.mlw
path: /opt/CAPEv2/storage/binaries/eeaddcadc45b26694507d87cbe8e3ab2e1d2a7145a9c179b7d78baa4f0f0347d
crc32: 70EC2DA0
md5: 9ac239c354abd23cf3c0590b3d7f003a
sha1: b1bd795eb4c60ee851902b125fb3f455c1ab6c9f
sha256: eeaddcadc45b26694507d87cbe8e3ab2e1d2a7145a9c179b7d78baa4f0f0347d
sha512: 738eaae258bfe0111808ef4e1d2657a14ae47b14a05976cd3c360e8f0d98869e60565104fa99bfbb32aad94e375515b6d513538dcc06de2c7d801b75dbb1f841
ssdeep: 12288:iqZiMwQJXx6a/YvRcFKBsX9Da2XbJda3Q93i8OPowY79pk/DCWN:7ZiUJXca/VQBIe2dhi8OP3YGv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T143652320C1D180C9C6FB0FBA56305EF41B969C75FA3662976489F48D723C9E9C5BE2C4
sha3_384: 769d1f9636ad64bab85c9816abcc62f2adc4e738f3fe24032783ab51fa7402ad59da5a5b70d0782e03cd78ab54a5b749
ep_bytes: e8870c1600e935fdffff558bec81ec28
timestamp: 2006-10-27 07:19:27

Version Info:

CompanyName: Microsoft Corporation
FileDescription: GrooveStdURLLauncher Utility
FileVersion: 0004, 0002, 0000, 0000
InternalName: GrooveStdURLLauncher
LegalCopyright: © 2006 Microsoft Corporation. All rights reserved.
OriginalFilename: GrooveStdURLLauncher.exe
ProductName: GrooveStdURLLauncher Utility
ProductVersion: 0004, 0002, 0000, 0000
Translation: 0x0000 0x04b0

Trojan:Win32/Phonzy.B!ml also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanWin32.Expiro.Gen.7
ClamAVWin.Virus.Expiro-10005873-0
FireEyeGeneric.mg.9ac239c354abd23c
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
ALYacWin32.Expiro.Gen.7
MalwarebytesExpiro.Virus.FileInfector.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
Cybereasonmalicious.eb4c60
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Vitro [Inf]
TACHYONVirus/W32.Movia
SophosW32/Moiva-C
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
EmsisoftWin32.Expiro.Gen.7 (B)
IkarusExpiro.Win32
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
Kingsoftmalware.kb.a.977
MicrosoftTrojan:Win32/Phonzy.B!ml
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
VaristW32/Expiro.AU.gen!Eldorado
Acronissuspicious
MAXmalware (ai score=80)
VBA32Trojan.Sabsik.TE
Cylanceunsafe
PandaW32/Moyv.A
RisingTrojan.Generic@AI.83 (RDML:OV1RLJ9VDYcievARtbapHw)
SentinelOneStatic AI – Malicious PE
FortinetW32/Expiro.NDP!tr
AVGWin32:Vitro [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Phonzy.B!ml?

Trojan:Win32/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment