Trojan

Trojan.Win32.Reconyc.obnp malicious file

Malware Removal

The Trojan.Win32.Reconyc.obnp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Reconyc.obnp virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Creates a slightly modified copy of itself

How to determine Trojan.Win32.Reconyc.obnp?


File Info:

crc32: FF3C6CE0
md5: 6953ebe5bb27686ac5cca3c8334b5bf5
name: 6953EBE5BB27686AC5CCA3C8334B5BF5.mlw
sha1: 6c43b75f08edcbf55e876ea2f8749497cb8b5134
sha256: 54c7d04790a36c11419f7a16d9f1464174f9aa8c3cf84fdd8b2dd58a8d825fad
sha512: abed3021e6e5f9f003ec5b316d02826b13bdbc4b6ebd81f9ead707b0a0f83dd2c155ec265f0596e26fba09e96604d21eb12624baab140dfbacb8e632dfc1b381
ssdeep: 6144:s2Nuuq9g/Mf38Cb/U19xS2RwK0Olg9YstAEDvK8yc7FwU:Bug/MfdU1TSfIOHDTKomU
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Reconyc.obnp also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.733936
FireEyeGeneric.mg.6953ebe5bb27686a
CAT-QuickHealTrojan.Skeeyah.J1
ALYacGen:Variant.Razy.733936
CylanceUnsafe
AegisLabTrojan.Win32.Reconyc.4!c
SangforMalware
K7AntiVirusTrojan ( 005393141 )
BitDefenderGen:Variant.Razy.733936
K7GWTrojan ( 005393141 )
Cybereasonmalicious.5bb276
BitDefenderThetaGen:NN.ZexaF.34804.rCZ@aGdGykg
CyrenW32/Kryptik.BQP.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Malware.Razy-6912779-0
KasperskyTrojan.Win32.Reconyc.obnp
AlibabaTrojan:Win32/Reconyc.7df2663f
Ad-AwareGen:Variant.Razy.733936
SophosML/PE-A + Mal/Inject-GJ
ComodoTrojWare.Win32.Kryptik.TLS@812zm8
F-SecureHeuristic.HEUR/AGEN.1140318
DrWebTrojan.Siggen9.17438
ZillyaTrojan.Generic.Win32.235867
TrendMicroTROJ_GEN.R002C0DB221
McAfee-GW-EditionBehavesLike.Win32.Nuwardam.dc
EmsisoftGen:Variant.Razy.733936 (B)
IkarusTrojan-Downloader.Win32.FakeAlert
GDataGen:Variant.Razy.733936
JiangminTrojan.Generic.cmjak
AviraHEUR/AGEN.1140318
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Kryptik.GIRH
ArcabitTrojan.Razy.DB32F0
ZoneAlarmTrojan.Win32.Reconyc.obnp
MicrosoftVirTool:Win32/CeeInject.AKZ!bit
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CeeInject.R237089
Acronissuspicious
McAfeePacked-FJB!6953EBE5BB27
VBA32Trojan.Tiggre
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.GIRH
TrendMicro-HouseCallTROJ_GEN.R002C0DB221
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
YandexTrojan.GenAsa!0xM7zILK7cg
SentinelOneStatic AI – Malicious PE – Downloader
FortinetW32/Zusy.304525!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.CeeInject.HxMBCgwA

How to remove Trojan.Win32.Reconyc.obnp?

Trojan.Win32.Reconyc.obnp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment