Trojan

Trojan:Win32/Znyonm information

Malware Removal

The Trojan:Win32/Znyonm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Znyonm virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Znyonm?


File Info:

name: A5361DEA0D691CAFD255.mlw
path: /opt/CAPEv2/storage/binaries/433bb5c159884f76056330e36138fae40b5cfea14d1b239c3665f94775426267
crc32: BE9A8E1F
md5: a5361dea0d691cafd2551e5c65a182ce
sha1: 29d303ce679f7a80684aaa986af86e2e0ef0029e
sha256: 433bb5c159884f76056330e36138fae40b5cfea14d1b239c3665f94775426267
sha512: 1b7b530cd9b039d70b3f61535009232ce3e242874e1752d570e9389f3ec6ab579abe43084f59370689ac18084da44c6eadef1a305f3e37784c881e21baa42992
ssdeep: 6144:vYa6OOjkaA2ORCGzTbcadnalQk23IbP0HV7gOqFBqoBieyyjcj46H:vYIGFA2nGFnaz23IbcHV71kXU5R4S
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12A541209676094BAE9A341706E7D879BFFEED81654608B1B0F204B187DB2752C81FB62
sha3_384: 6af7f1b1cb2db64996438994aaf7698c0187161221dc335a69308abe24e632fde30880d809bd5f9114cca50f1572cd6d
ep_bytes: 558bec81ecf40300005356576a205f33
timestamp: 2021-09-25 21:56:47

Version Info:

CompanyName: douper
FileDescription: blackpot
LegalCopyright: Copyright uninvincibleness
ProductName: 99.91.68.56
Translation: 0x0409 0x04b0

Trojan:Win32/Znyonm also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Strab.4!c
AVGWin32:MalwareX-gen [Trj]
DrWebTrojan.PWS.Tibia.2802
MicroWorld-eScanTrojan.GenericKD.69420777
FireEyeGeneric.mg.a5361dea0d691caf
SkyhighBehavesLike.Win32.CoinMiner.dc
McAfeeArtemis!A5361DEA0D69
MalwarebytesMalware.AI.4102079012
SangforSuspicious.Win32.Save.ins
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojan:Win32/Strab.e14aaa10
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36802.hmW@ai9BtSi
VirITTrojan.Win32.Genus.TGR
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32Win32/Formbook.AA
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan.Win32.Strab.gen
BitDefenderTrojan.GenericKD.69420777
NANO-AntivirusTrojan.Win32.Strab.kbcqrr
AvastWin32:MalwareX-gen [Trj]
RisingTrojan.Lokibot!8.F1B5 (TFE:5:F8sldKi1U7H)
EmsisoftTrojan.GenericKD.69420777 (B)
F-SecureHeuristic.HEUR/AGEN.1372050
VIPRETrojan.GenericKD.69420777
TrendMicroTROJ_GEN.R002C0XB424
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GoogleDetected
AviraHEUR/AGEN.1373280
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Lokibot
KingsoftWin32.Trojan.Strab.gen
MicrosoftTrojan:Win32/Znyonm
XcitiumMalware@#8ob2n29dc5xg
ArcabitTrojan.Generic.D42346E9
ZoneAlarmHEUR:Trojan.Win32.Strab.gen
GDataTrojan.GenericKD.69420777
VaristW32/ABTrojan.IMZU-2874
AhnLab-V3Trojan/Win.LokiBot.R606942
ALYacTrojan.GenericKD.69420777
VBA32BScope.Trojan.Injector
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0XB424
TencentWin32.Trojan.Strab.Xmhl
IkarusTrojan.Win32.Injector
FortinetNSIS/Agent.DCAC!tr
Cybereasonmalicious.a0d691
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Formbook.AA

How to remove Trojan:Win32/Znyonm?

Trojan:Win32/Znyonm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment