Malware

Downloader.Win32.Snojan.evpn malicious file

Malware Removal

The Downloader.Win32.Snojan.evpn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Snojan.evpn virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

api.baizhu.cc

How to determine Downloader.Win32.Snojan.evpn?


File Info:

crc32: 3234A790
md5: 536cb3b861b19afc889d9c6fb43dee24
name: lbwmryyb.exe
sha1: 76b6cc49e0c7860301a8afbc56d420791fa87a11
sha256: d540e7934d1398f2b6b19e7b7c17e12c387866386f555b8444029ad713312e7c
sha512: 1e9b9914a609e2f525d45f8beeb09ba8d2fe94b56f4a2ea740c105d409baec985d77fc725b6520d24d940d23f4628f43a0b1a3f1daf323ccd11d84f21d0052c4
ssdeep: 24576:A9bnp6KVuOvEYFNbYxC8ikOqKJP5EsC1fK8oiZ6XBIogtRd3NUxW:q6K+iN8ikOhvY1fGK6XBIogLd3+W
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017
InternalName: x667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 2.1.0.1227
ProductName: x667ax80fdx4e0bx8f7dx5668.exe
ProductVersion: 2.1.0.1227
FileDescription: x667ax80fdx4e0bx8f7dx5668
OriginalFilename: x667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

Downloader.Win32.Snojan.evpn also known as:

MicroWorld-eScanTrojan.GenericKD.30954567
CAT-QuickHealTrojan.GenericPMF.S2063435
McAfeePUP-XCK-VE
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 005524301 )
BitDefenderTrojan.GenericKD.30954567
K7GWAdware ( 005524301 )
CrowdStrikewin/malicious_confidence_60% (D)
Invinceaheuristic
CyrenW32/S-057ae34f!Eldorado
SymantecTrojan.Gen.2
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-6438326-0
Kasperskynot-a-virus:Downloader.Win32.Snojan.evpn
AlibabaDownloader:Win32/Snojan.65f6067f
NANO-AntivirusRiskware.Win32.Qjwmonkey.ewsjtt
ViRobotAdware.Zusy.1286352
SUPERAntiSpywareAdware.QJWMonkey/Variant
RisingTrojan.Generic@ML.87 (RDMK:sZrbkgG/0azr5kntABQpbA)
Ad-AwareTrojan.GenericKD.30954567
SophosQjMonkey (PUA)
ComodoApplication.Win32.AdWare.Qjwmonkey.H@7pvzrs
DrWebAdware.Qjwmonkey.131
ZillyaAdware.Qjwmonkey.Win32.372
TrendMicroADW_QJWMONKEY
McAfee-GW-EditionPUP-XCK-VE
FireEyeGeneric.mg.536cb3b861b19afc
EmsisoftTrojan.GenericKD.30954567 (B)
IkarusTrojan.Win32.Agent
F-ProtW32/S-057ae34f!Eldorado
JiangminDownloader.Generic.ieo
WebrootW32.Adware.Gen
AviraADWARE/Qjwmonkey.ofeiu
Antiy-AVLRiskWare[Downloader]/Win32.Snojan
MicrosoftBrowserModifier:Win32/Qiwmonk
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1D85447
ZoneAlarmnot-a-virus:Downloader.Win32.Snojan.evpn
GDataTrojan.GenericKD.30954567
AhnLab-V3PUP/Win32.Qiwmonk.R222380
VBA32BScope.Downloader.Snojan
ALYacTrojan.GenericKD.30954567
MAXmalware (ai score=100)
MalwarebytesTrojan.MalPack.PS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.H
TrendMicro-HouseCallADW_QJWMONKEY
YandexPUA.Downloader!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetAdware/Qjwmonkey
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.861b19
AvastWin32:Adware-gen [Adw]

How to remove Downloader.Win32.Snojan.evpn?

Downloader.Win32.Snojan.evpn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment