Trojan

Trojan.Sennoma (file analysis)

Malware Removal

The Trojan.Sennoma is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Sennoma virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • A system process is generating network traffic likely as a result of process injection
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan.Sennoma?


File Info:

crc32: 3EE09A7C
md5: 4366f35a9a0184a751fda55727a0b170
name: 4366F35A9A0184A751FDA55727A0B170.mlw
sha1: 09db6a6b87d8ac4754b6d0ad8570cca97d12ffcb
sha256: 704e4fab19da21718fff7eae11e951132d8205fb8f866b2abdeb1df72743bcd8
sha512: 3ae7e24b6f3c4976e497aa5aeca39639801fc46113f75c878130c5b42835efa1b2f6b344129fca38d69bb81483564fb0130376d8c9893d480403c1d3fc4dc8a5
ssdeep: 3072:dwu7VuVNOUP+96PzDYD4KXEFyI/Qu1zM8V6kNX+EEqiQl:+YYVNY63YD4mEFypuSP0XIg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Sennoma also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005118de1 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop7.26158
CynetMalicious (score: 100)
ALYacGen:Heur.Ransom.Lukitos.1
CylanceUnsafe
ZillyaTrojan.SennomaCRTD.Win32.12021
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaVirTool:Win32/Obfuscator.29b6a72d
K7GWTrojan ( 005118de1 )
Cybereasonmalicious.a9a018
SymantecPacked.Generic.493
ESET-NOD32a variant of Win32/Kryptik.FRTO
APEXMalicious
AvastWin32:DangerousSig [Trj]
ClamAVWin.Packed.Brresmon-7598574-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Ransom.Lukitos.1
NANO-AntivirusTrojan.Win32.Kryptik.eqoyxo
MicroWorld-eScanGen:Heur.Ransom.Lukitos.1
TencentWin32.Trojan.Sennoma.Pbfi
Ad-AwareGen:Heur.Ransom.Lukitos.1
SophosML/PE-A + Mal/Elenoocka-E
ComodoTrojWare.Win32.TrojanDropper.Evotob.A@70f09z
BitDefenderThetaGen:NN.ZexaF.34670.kqX@ameUyVo
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.SMALY0
McAfee-GW-EditionRansomware-FMEU!4366F35A9A01
FireEyeGeneric.mg.4366f35a9a0184a7
EmsisoftGen:Heur.Ransom.Lukitos.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bmafa
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1116789
eGambitUnsafe.AI_Score_99%
MicrosoftVirTool:Win32/Obfuscator.ARL
AegisLabTrojan.Win32.Sennoma.4!c
GDataGen:Heur.Ransom.Lukitos.1
TACHYONTrojan/W32.Sennoma.168912.B
AhnLab-V3Trojan/Win32.Zerber.R213394
Acronissuspicious
McAfeeRansomware-FMEU!4366F35A9A01
MAXmalware (ai score=100)
VBA32Trojan.Sennoma
MalwarebytesCerber.Ransom.Encrypt.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_CERBER.SMALY0
RisingRansom.Cerber!8.3058 (TFE:dGZlOgIZXhdxz3DzSQ)
YandexTrojan.GenAsa!QPfU+CyaSmg
IkarusPUA.FileTour
FortinetW32/Kryptik.FSHI!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Obfuscated.HxQBEpsA

How to remove Trojan.Sennoma?

Trojan.Sennoma removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment