Trojan

About “Trojan:Win32/Znyonm” infection

Malware Removal

The Trojan:Win32/Znyonm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Znyonm virus can do?

  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Trojan:Win32/Znyonm?


File Info:

name: 9262AB9F3F83BE8D5B14.mlw
path: /opt/CAPEv2/storage/binaries/8573dc1d46e6e652e2daa8b3bcebeb606f78c70dfb1251275df2f01485412640
crc32: 3B11BAC2
md5: 9262ab9f3f83be8d5b14ec198db2b479
sha1: 4939f7bc00e599bcc9410b482c1c7f61611da18b
sha256: 8573dc1d46e6e652e2daa8b3bcebeb606f78c70dfb1251275df2f01485412640
sha512: a470f26696e4b954f6b54c58815a13bf8b6bd623d26bafacd4d93e3be60a33cf6b50ed677aaa815fb7a71c2ee9e83ec1947962c995a82c165319290f4a710762
ssdeep: 49152:KRzhdP1WAnRP+m5STLGNnepaKkhL3Us0oRiRVNVy:K3d9RP+4lepaKkhL3Us0oRiR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15B95BF217940C1B6FC630270A93FBB764939AD685B7410DBA3C83E3D19721D36A3676B
sha3_384: 6b9045244f77378f43c9e5dddbd3aa74181362c217acd73ad938bb9f3de600d89d647b906f3123cb0c321008bdb51a8f
ep_bytes: e869100000e98efeffff558bec5de9d9
timestamp: 2023-09-27 03:11:49

Version Info:

Comments: 迅捷视频剪辑软件
CompanyName: 上海互盾信息科技有限公司
FileDescription: 迅捷视频剪辑软件
FileVersion: 1.7.5
InternalName: 迅捷视频剪辑软件
LegalCopyright: 上海互盾信息科技有限公司
LegalTrademarks: 互盾科技
OriginalFilename: 迅捷视频剪辑软件
PrivateBuild: 迅捷视频剪辑软件
ProductName: 迅捷视频剪辑软件
ProductVersion: 1.7.5
SpecialBuild: 迅捷视频剪辑软件
Translation: 0x0804 0x04b0

Trojan:Win32/Znyonm also known as:

LionicTrojan.Win32.Hudun.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.70234278
FireEyeTrojan.GenericKD.70234278
SkyhighBehavesLike.Win32.Dropper.th
McAfeeArtemis!9262AB9F3F83
VIPRETrojan.GenericKD.70234278
SangforTrojan.Win32.Hudun.Va3a
CrowdStrikewin/grayware_confidence_100% (W)
BitDefenderTrojan.GenericKD.70234278
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Hudun.A potentially unwanted
RisingTrojan.Znyonm!8.18A3A (CLOUD)
EmsisoftTrojan.GenericKD.70234278 (B)
SophosGeneric Reputation PUA (PUA)
IkarusPUA.Hudun
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Znyonm
GridinsoftTrojan.Win32.Agent.sa
ArcabitTrojan.Generic.D42FB0A6
GDataTrojan.GenericKD.70234278
BitDefenderThetaGen:NN.ZexaF.36792.8H0@aOKhMspj
ALYacTrojan.GenericKD.70234278
DeepInstinctMALICIOUS
Cylanceunsafe
FortinetRiskware/Hudun
AVGWin32:MiscX-gen [PUP]
AvastWin32:MiscX-gen [PUP]

How to remove Trojan:Win32/Znyonm?

Trojan:Win32/Znyonm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment