Trojan

About “Trojan:Win32/Phonzy.C!ml” infection

Malware Removal

The Trojan:Win32/Phonzy.C!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.C!ml virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Phonzy.C!ml?


File Info:

name: BAAFC87CEC813A7C55E0.mlw
path: /opt/CAPEv2/storage/binaries/276efb49d1b2f16c4d2c4879e5e69c1c4b77f481e61bd41df73c1cb4f43ad18c
crc32: B5AAC1CA
md5: baafc87cec813a7c55e077999ac8adf9
sha1: b5bd28b78e2dc4e8a9d2f3877e8f4e1583755d4d
sha256: 276efb49d1b2f16c4d2c4879e5e69c1c4b77f481e61bd41df73c1cb4f43ad18c
sha512: 94e2dd41b64b2cd58281b079688137233866bcdc8d775036b78146a98178e0f3233fd1c4ade12cf73c7e649349a40ad6c30a990c90ab4677eae118d7a479d6dd
ssdeep: 12288:3o6Gt/sB1KcYmqgZvAMlUoUjG+YKtMfnkOeZb5JYiNAgAPh:ct/sBlDqgZQd6XKtiMJYiPU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T193D4221EF5C2C67DE67B1B362DA9B400A1B6361CDD06617BB3D17E1A3E390434A39263
sha3_384: 5844cb919d3a5c0474d1c72568d9b508aea32f50df293f3519729320bbdd7763a4bb14e8fc96189a556c823c183203a6
ep_bytes: e82cfcffffe933fdffffff2590110030
timestamp: 2006-10-27 04:30:58

Version Info:

CompanyName: Microsoft Corporation
FileDescription: XML Editor
FileVersion: 12.0.4518.1014
InternalName: msoxmled.exe
LegalCopyright: © 2006 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
LegalTrademarks3: InfoPath® is a registered trademark of Microsoft Corporation.
OriginalFilename: msoxmled.exe
ProductName: Microsoft Office InfoPath
ProductVersion: 12.0.4518.1014
Translation: 0x0000 0x04e4

Trojan:Win32/Phonzy.C!ml also known as:

CyrenCloudW32/Expiro.AU.gen!Eldorado
BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
tehtrisGeneric.Malware
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.baafc87cec813a7c
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Sality.jc
ALYacWin32.Expiro.Gen.7
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaVirus:Win32/Moiva.3e5ecfee
K7GWVirus ( 005a8b911 )
K7AntiVirusVirus ( 005a8b911 )
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32Win32/Expiro.CU
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Expiro-9941636-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
Ad-AwareWin32.Expiro.Gen.7
SophosW32/Moiva-A
F-SecureTrojan.TR/Patched.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
Trapminemalicious.high.ml.score
EmsisoftWin32.Expiro.Gen.7 (B)
IkarusVirus.Win32.Ausiv
JiangminTrojan.Generic.hnxtm
VaristW32/Expiro.AU.gen!Eldorado
AviraTR/Patched.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftTrojan:Win32/Phonzy.C!ml
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
GoogleDetected
MAXmalware (ai score=89)
VBA32Trojan.Sabsik.TE
PandaW32/Moyv.A
RisingTrojan.Generic@AI.91 (RDML:mnN6INL1p2M7WG6IRaZ4QA)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:FileInfector-C [Heur]
Cybereasonmalicious.78e2dc
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Phonzy.C!ml?

Trojan:Win32/Phonzy.C!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment