Trojan

Trojan:Win32/Znyonm information

Malware Removal

The Trojan:Win32/Znyonm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Znyonm virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Znyonm?


File Info:

name: 4C26A3F4EF5C7BA1E590.mlw
path: /opt/CAPEv2/storage/binaries/bca34717cac5dbbac51d5dab35282e3ccc8b82aecde78685e2190f11ce1897c1
crc32: 77C7F572
md5: 4c26a3f4ef5c7ba1e59082bd521046a2
sha1: d792c3b1af081467961146a722ca08d3fec3b530
sha256: bca34717cac5dbbac51d5dab35282e3ccc8b82aecde78685e2190f11ce1897c1
sha512: f75e507fcfa241540ed6d955ba4567b3c30ef2a0f9cca306f87c3ba5bb6128cd188832cde9962b893933d3481acad76270015699468e143de9fff20e1a1d0156
ssdeep: 98304:PSXK6n16USrvm3B7xEqAukmHCiouQKGuQj:Yn1Gc3NpouQKGuQj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DA469E42B2F64061E93020B2D287FF3B7926FD95D8E449E78F28DA9C865CB105F6346D
sha3_384: 054c1a0dccbd00f9382f8f64ea6cc8fe315ec90984ab2ae47f95c53ac260a8cd3a56e2b591f6ac956662e6b3cb1b33eb
ep_bytes: 558bec6aff6880eb8e006824994a0064
timestamp: 2023-10-19 05:31:59

Version Info:

FileVersion: 1.0.0.0
FileDescription: WD游戏登陆
ProductName: 登录器
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Trojan:Win32/Znyonm also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.liRL
Elasticmalicious (high confidence)
FireEyeGeneric.mg.4c26a3f4ef5c7ba1
SkyhighBehavesLike.Win32.Generic.tc
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
BitDefenderThetaGen:NN.ZexaF.36802.@t0@aOCyZRbb
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002H0CKF23
ClamAVWin.Malware.Gotango-7000352-0
AvastWin32:Evo-gen [Trj]
SophosMal/Generic-S
GoogleDetected
Trapminemalicious.moderate.ml.score
SentinelOneStatic AI – Malicious PE
VaristW32/OnlineGames.HG.gen!Eldorado
Antiy-AVLRiskWare/Win32.FlyStudio.a
MicrosoftTrojan:Win32/Znyonm
XcitiumWorm.Win32.Dropper.RA@1qraug
GDataWin32.Trojan.PSE.161DS2T
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R534780
McAfeeArtemis!4C26A3F4EF5C
VBA32BScope.Backdoor.Poison
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Chgt.AD
RisingTrojan.Generic@AI.99 (RDML:p+nc6w0c6JOIbTvN9BZAEA)
IkarusTrojan.Win32
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.PHP!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan:Win32/Znyonm?

Trojan:Win32/Znyonm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment