Trojan

Trojan:Win32/Phonzy.C!ml (file analysis)

Malware Removal

The Trojan:Win32/Phonzy.C!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.C!ml virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Authenticode signature is invalid

How to determine Trojan:Win32/Phonzy.C!ml?


File Info:

name: C88D95E30F1D413DA33B.mlw
path: /opt/CAPEv2/storage/binaries/d1f208c0969db8b77bda677fb1497776c5d9611b4134cb49b047e140a7a35337
crc32: 57F5A83E
md5: c88d95e30f1d413da33b2faf8f59adf1
sha1: 79b66059c8cea28ca9eb5bcff1929dd62b44dfef
sha256: d1f208c0969db8b77bda677fb1497776c5d9611b4134cb49b047e140a7a35337
sha512: d470e24bce552cd41052447b4f772cc49674a158886e5e283210dbd43abeb43e0764aa5259ad8127c8b7ca3957ec846fe8b9fb326f87e600788cfd65489e201d
ssdeep: 12288:twMGt/sB1KcYmqgZvAMlUoUjG+YKtMfnkOeZb5JYiNAgAPh:tst/sBlDqgZQd6XKtiMJYiPU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17145232B38C3C0BADBAB57752E68BA04D5BB322C9F5870D793C5B4592E3C0825C75227
sha3_384: 86e73c0b0bcb80318a2087726460ae6a4767dd8b7794c53a62e47b27eee6079c16677d19e1a74d3976fb3dc1d4f9c30c
ep_bytes: e863060000e978feffffcccccccccccc
timestamp: 2021-02-24 21:27:00

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: AcroTextExtractor
FileVersion: 21.1.20142.424128
LegalCopyright: Copyright 1984-2021 Adobe Systems Incorporated and its licensors. All rights reserved.
OriginalFilename: AcroTextExtractor.exe
ProductName: Adobe Acrobat text extractor for non-PDF files
ProductVersion: 21.1.20142.424128
Translation: 0x0409 0x04b0

Trojan:Win32/Phonzy.C!ml also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.c88d95e30f1d413d
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
ALYacWin32.Expiro.Gen.7
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Moiva.8931c061
K7GWVirus ( 005a8b911 )
SymantecW32.Xpiro.J!dam
ESET-NOD32Win32/Expiro.CU
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Expiro-9941636-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
Trapminemalicious.moderate.ml.score
SophosW32/Moiva-A
SentinelOneStatic AI – Malicious PE
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftTrojan:Win32/Phonzy.C!ml
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Trojan.PSE.12S6KP6
GoogleDetected
Acronissuspicious
MAXmalware (ai score=80)
VBA32Trojan.Sabsik.TE
MalwarebytesVirus.M0yv
PandaW32/Moyv.A
RisingTrojan.Generic@AI.86 (RDML:nTyoctBeXG74IR4hDK1rgw)
IkarusTrojan.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Phonzy.C!ml?

Trojan:Win32/Phonzy.C!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment