Trojan:Script/Phonzy.A!ml and Trojan:Script/Phonzy.B!ml are Microsoft Defender family detections, not proof that every flagged file has one fixed behavior. Keep the item quarantined while you record the exact label and affected path, then check whether the file was only stored in an archive or browser download cache or actually ran. Treat an alert from an email script, unknown cloud link, crack, mod, or unsigned installer as unsafe until verified. If the file is your own freshly compiled build or comes from a trusted signed tool, update Defender, verify its source or hash, and submit the exact item to Microsoft before restoring it.
What should you do first?
- Save the exact label and path: note whether Defender says
Trojan:ScriptorTrojan:Win32, the A!ml/B!ml variant, and the full affected item. - Do not allow or restore blindly. Keep quarantine while you verify the source, signature or hash, and whether the alert returns.
- Separate stored from executed: a file found inside a ZIP, 7z, RAR, browser cache, or cloud download still needs removal, but running its script or installer raises the response to compromise cleanup.
- For your own build: rebuild from reviewed source on a clean machine, update Defender, and submit the exact output to Microsoft instead of excluding the whole build folder.
- If it executed, run a full scan, review startup entries, tasks, and browser extensions, then change important passwords from a clean device.
| Detection variants | Trojan:Script/Phonzy.A!ml, Trojan:Script/Phonzy.B!ml, and related Trojan:Win32/Phonzy.*!ml alerts |
| Detected by | Microsoft Defender Antivirus |
| Type | Defender family / machine-learning detection; the exact behavior is sample-specific |
| Best action | Quarantine, identify the affected path and source, remove the parent download or archive, update Defender, scan, and check persistence if anything ran |
What is Trojan:Script/Phonzy.A!ml or B!ml?
Microsoft Security Intelligence lists Trojan:Script/Phonzy.A!ml as a Defender script Trojan detection and says Defender detects and removes it [1]. Huntress describes Phonzy as a detection-family label whose behavior can vary by sample rather than one fixed malware codebase [4]. The label alone therefore cannot prove a specific capability. The affected item path, source, signature, and whether it executed are the practical evidence.
The Microsoft Defender detection name format still matters: Script or Win32 is the platform field, Phonzy is the family label, A or B is a variant, and !ml indicates machine-learning classification. A Win32 result does not automatically mean a different infection from a Script result, and an ML suffix does not make the alert harmless. Use the exact full label when searching or submitting the affected file.
Phonzy.A!ml in a ZIP, 7z, RAR, or MEGA download
Archive detections create false-positive anxiety because Defender may report the archive member rather than a file you intentionally ran. Do not judge the alert from the extension alone. A compressed file can contain scripts, shortcut files, HTML payloads, installers, or obfuscated JavaScript even when the outer archive looks ordinary.
- If the archive came from a crack, mod, game repack, password-protected link, or unknown MEGA folder, delete it and keep Defender’s quarantine.
- If the file came from your own project or a trusted vendor, compare hashes, redownload from the official source, update Defender security intelligence [3], and submit the exact file to Microsoft as an incorrect detection if evidence supports a false positive [2].
- If you only opened the archive but did not run anything, remove the archive/source and run a full scan. For general archive risk, see our guide on whether opening a ZIP or RAR file can give you a virus.
- If you executed a script, installer, or command from the archive, treat the event as a possible compromise and continue with the cleanup steps below.
Could a developer build or trusted utility be a false positive?
A freshly compiled plugin, unsigned automation script, self-extracting bundle, or uncommon utility can trigger an ML detection, but ownership of the source is evidence, not an automatic clean verdict. Rebuild from reviewed source on a clean machine, compare the output hash, verify the expected signer when one should exist, update Defender definitions, and submit the exact file to Microsoft. Do not create a broad exclusion for a workspace, Downloads, Temp, or an entire app folder while the result is unresolved.
If Windows Security asks to send or review a sample, the Defender sample-review guide explains the separate privacy and submission decision. A downloaded release that differs from your clean reproducible build should remain quarantined.
Can Phonzy.A!ml or B!ml be a false positive?
False positives are possible, especially with custom scripts, freshly compiled files, packed software, browser cache artifacts, or security tooling. The safer test is source plus execution state: a reproducible file from reviewed source that stays clean after updated scans is different from a script delivered through an ad, fake update, crack, or unknown cloud link. Avoid exclusions until Microsoft or another trusted analysis supports a clean verdict.
If the alert appeared after you ran an unknown game/mod installer or entered passwords afterward, also review account risk. Our infostealer detection and recovery guide covers password changes, session revocation, and browser-token exposure.
Why does the Phonzy alert keep coming back?
A repeated alert means Defender is seeing the same item again or a parent app, download, archive, browser component, task, or startup entry is recreating it. Match each new event to its affected path instead of clearing Protection History.
- Browser cache or Downloads: close the browser, remove the original download, review recent extensions, clear the relevant cache, and rescan.
- Archive or extracted folder: delete both the extracted item and the parent ZIP/7z/RAR or cloud download; otherwise extraction can trigger the same label again.
- App or developer output: update or repair the trusted app, compare the rebuilt file, and submit the exact repeated sample rather than excluding its folder.
- Startup, Task Scheduler, AppData, or Temp: treat recurrence as possible persistence, quarantine the visible item, inspect what launches it, and run an updated full or Offline scan.
How to remove Trojan:Script/Phonzy.A!ml or B!ml
- Open Windows Security and choose Remove or Quarantine for the Phonzy detection.
- Write down the affected item path, then delete the original download, archive, email attachment, or extracted folder that produced the alert.
- Update Microsoft Defender security intelligence before rescanning [3].
- Run a full scan. If the alert returns, or if the script ran before Defender blocked it, run Microsoft Defender Offline from Windows Security.
- Check Startup Apps, Task Scheduler, browser extensions, Run keys, and recently installed apps if the file executed.
- Change important passwords from a clean device if the script ran, opened a phishing page, or was bundled with a crack/mod/download manager.
- Run a second-opinion Gridinsoft Anti-Malware scan if Defender reports remediation incomplete, repeated detections, or suspicious startup/browser behavior.
If Phonzy came from an archive, MEGA download, crack, mod, or fake update, deleting one script may not remove the downloader or source package. Scan for the item that keeps extracting, restoring, or launching the script alert.
Defender can quarantine the visible file, but repeated alerts may mean a loader, scheduled task, service, browser change, or bundled component is recreating it. Scan the PC before trusting the cleanup.
Find what keeps recreating the script alertFAQ
Is Trojan:Script/Phonzy.A!ml the same as Phonzy.B!ml?
They are related Defender family variants, but the exact sample behavior can differ. Use the full label from the alert and make the decision from the affected path, source, signature, and whether anything executed.
Why does Defender sometimes say Trojan:Win32/Phonzy instead of Trojan:Script/Phonzy?
Script and Win32 are platform fields in the Defender name. They help identify the alert but do not by themselves prove a separate malware family or fixed behavior. Keep the entire label for searches and file submission.
Can my freshly compiled app be a Phonzy false positive?
Yes, an uncommon build can be misclassified, but do not restore it on that assumption. Rebuild from reviewed source, compare hashes, update Defender, and submit the exact output to Microsoft before allowing it.
What does remediation incomplete mean?
Defender could not confirm every cleanup step. Remove the original archive or download, reboot, update Defender, run a full or Offline scan, and investigate what recreates the item if the same path returns.
Should I restore a Phonzy file if Reddit says it is a false positive?
No. Keep it quarantined until you can verify the source, hash, signature, clean rescans, and Microsoft submission result. Forum reassurance is not enough for an unknown script or archive.
Can a Phonzy detection mean password risk?
Only the label cannot prove credential theft. Change passwords and revoke sessions from a clean device if the detected file ran, opened a phishing page, installed another payload, or appeared with unauthorized account activity.
References
- Microsoft Security Intelligence. “Trojan:Script/Phonzy.A!ml threat description.” Microsoft, published January 21, 2021, accessed August 21, 2026. Microsoft Phonzy.A!ml threat description.
- Microsoft Security Intelligence. “Submit a file for malware analysis.” Microsoft, accessed August 21, 2026. Microsoft file submission portal.
- Microsoft Security Intelligence. “Security intelligence updates for Microsoft Defender Antivirus and other Microsoft antimalware.” Microsoft, accessed August 21, 2026. Microsoft Defender security intelligence updates.
- Lizzie Danielson. “Phonzy Malware.” Huntress Threat Library, published December 23, 2025, updated August 14, 2026, accessed August 21, 2026. Huntress Phonzy family overview.

