Trojan

Trojan:Win32/Znyonm removal

Malware Removal

The Trojan:Win32/Znyonm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Znyonm virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Znyonm?


File Info:

name: F142DFE1F0239AB0ECC6.mlw
path: /opt/CAPEv2/storage/binaries/a4161c88df671b1ccad2887337029381ca4dc605f39d57ce436bb820b6e3ced3
crc32: 2EA4B6DC
md5: f142dfe1f0239ab0ecc60ef920ccddcb
sha1: f9c1f12b1e6aa909c7863bf2be09ae51d794f184
sha256: a4161c88df671b1ccad2887337029381ca4dc605f39d57ce436bb820b6e3ced3
sha512: 5d5b249dd0e66234b221b9b9c8a59e0f498af74092d900402c34dde69cc6f97695c180fdb863dedf471b9202354a797ca06b0f2b4992d2b32824dc14d6f76f01
ssdeep: 196608:91OYtBGeeUAkfxSHFJrafriLsKGLuySUEwcViOfMuSMr1xTdaUgl2x:3OYtBGxex2JATPuySP1VisMHMRpL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T152763329BCED487BF6D30B35D9717F5265E8822C65318C67ABEE8A8C0D3F61C8571602
sha3_384: baf701700b520046ab9b24e63ae1e46514fc24b2345ea0fdd453fc1d27b3378e846f032f34720862a7fa0d1e2921a88d
ep_bytes: 558bec6aff68e0b94100682c4a410064
timestamp: 2010-11-18 16:27:35

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Setup SFX
FileVersion: 9.20
InternalName: 7zS.sfx
LegalCopyright: Copyright (c) 1999-2010 Igor Pavlov
OriginalFilename: 7zS.sfx.exe
ProductName: 7-Zip
ProductVersion: 9.20
Translation: 0x0409 0x04b0

Trojan:Win32/Znyonm also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Neoreklami.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.70196137
FireEyeTrojan.GenericKD.70196137
SkyhighBehavesLike.Win32.Dropper.wc
SangforAdware.Win32.Neoreklami.Vb6i
CrowdStrikewin/grayware_confidence_90% (D)
BitDefenderTrojan.GenericKD.70196137
BitDefenderThetaGen:NN.ZexaF.36792.@Z0@aCq3PTci
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Neoreklami.NN
APEXMalicious
KasperskyTrojan.Win32.Lolbas.acl
RisingTrojan.Sdum!8.1155F (TFE:2:grN22HR5FJE)
SophosGeneric Reputation PUA (PUA)
F-SecureAdware.ADWARE/Neoreklami.gldlu
VIPRETrojan.GenericKD.70196137
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.70196137 (B)
IkarusPUA.Neoreklami
MAXmalware (ai score=87)
GoogleDetected
AviraADWARE/Neoreklami.gldlu
VaristW32/ABAdware.UPFE-6029
Antiy-AVLGrayWare[AdWare]/Win32.Neoreklami
MicrosoftTrojan:Win32/Znyonm
ArcabitTrojan.Generic.D42F1BA9
ZoneAlarmTrojan.Win32.Lolbas.acl
GDataTrojan.GenericKD.70196137
CynetMalicious (score: 100)
McAfeeArtemis!F142DFE1F023
DeepInstinctMALICIOUS
MalwarebytesGeneric.Adware.Agent.DDS
SentinelOneStatic AI – Suspicious SFX
MaxSecureTrojan.Malware.121218.susgen
FortinetAdware/Neoreklami
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]

How to remove Trojan:Win32/Znyonm?

Trojan:Win32/Znyonm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment