Trojan

How to remove “Trojan:Win32/Phonzy.B!ml”?

Malware Removal

The Trojan:Win32/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.B!ml virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan:Win32/Phonzy.B!ml?


File Info:

name: 9FB42694B828E02B7A72.mlw
path: /opt/CAPEv2/storage/binaries/de108f1d25d02cf19bf01bd822b1b599f12cb6fd70433792713261df57c079c1
crc32: 57B3AF5B
md5: 9fb42694b828e02b7a72a2ccac118b45
sha1: ce76b73d80b251b7dd771eafc0d529d3cf1b8919
sha256: de108f1d25d02cf19bf01bd822b1b599f12cb6fd70433792713261df57c079c1
sha512: 14ee52f6bb1da0ea534db25339a5dd8b2bdc76cf4a072e4167c743b15d70f67bb92a8715a6f023e6c456384dc89b189eba68bb48a7fa9d0168f39a474a67bbd5
ssdeep: 768:ZapYjWydZNHVzXU6aFMl2wQAYvZzapYjWydZNHVzXq6aFMl2wQAYvZ:Z2YjW1Mloz2YjW/Mlo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EB644BE3FE91CAB2D0128EFC5DA78155B6E737303F7805C1B5AA8ECDA9795C01A0E056
sha3_384: 6c93cc831eeed79e1ae1d2f206a01fd71528366247875702a3e7cac9e8b6f73c2915e262ac744426a7e2a13c53f975f9
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan:Win32/Phonzy.B!ml also known as:

BkavW32.AIDetectMalware
DrWebWin32.HLLW.Kazaa.924
CynetMalicious (score: 100)
SkyhighGenericRXUX-FE!9FB42694B828
McAfeeGenericRXUX-FE!9FB42694B828
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusUnwanted-Program ( 0059886f1 )
K7GWUnwanted-Program ( 0059886f1 )
Cybereasonmalicious.d80b25
ArcabitTrojan.Agent.EICV
SymantecTrojan.Gen.MBT
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/Delf.NAY
APEXMalicious
ClamAVWin.Malware.Delf-6737076-0
BitDefenderTrojan.Agent.EICV
MicroWorld-eScanTrojan.Agent.EICV
AvastWin32:Delf-SVI [Trj]
RisingVirus.BagarBubba!1.D52A (CLASSIC)
EmsisoftTrojan.Agent.EICV (B)
VIPRETrojan.Agent.EICV
TrendMicroMal_Krap-8
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.9fb42694b828e02b
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agent.dqxf
VaristW32/Agent.DMD.gen!Eldorado
MAXmalware (ai score=81)
XcitiumHeur.Corrupt.PE@1z141z3
MicrosoftTrojan:Win32/Phonzy.B!ml
GDataWin32.Trojan.Agent.YE2GW5
GoogleDetected
VBA32Worm.Delf
ALYacTrojan.Agent.EICV
Cylanceunsafe
TrendMicro-HouseCallMal_Krap-8
TencentVirus.Win32.Lamer.fh
IkarusWorm.Win32.Eggnog
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Delf.NAY
AVGWin32:Delf-SVI [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Phonzy.B!ml?

Trojan:Win32/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment