Trojan

How to remove “Trojan:Win32/Znyonm”?

Malware Removal

The Trojan:Win32/Znyonm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Znyonm virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Znyonm?


File Info:

name: AC0E7D5A1B8E8B121DF7.mlw
path: /opt/CAPEv2/storage/binaries/c468461487f71d14d9f37e02aa38c2cadcf4adadcf059ee0975f620cca38bc35
crc32: D39D6702
md5: ac0e7d5a1b8e8b121df789532ce43d20
sha1: 21bc33b56bc5adb60b7721bf25e13c9cc764324c
sha256: c468461487f71d14d9f37e02aa38c2cadcf4adadcf059ee0975f620cca38bc35
sha512: 0e36a97c8e251eb681352d7b108767269d2f6a22f677f31155659a5392de1d0282d5f65f165675497a0630f708646d3ade17464441bed44d73efa8b91708e999
ssdeep: 49152:AG0lqR0sEyjIP3Z78Uf1Ibaeij5iE30vpuwLXwvcBgbN1Hwg/vfP/vfP/vfP/vft:KMSqU783Q0R1gcIrVKSDhrdqnnnnn+mk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BE465A92FDAB40F6EA0714346197266F1B345D084F75CFD7E688BB2DE93A2D20C76206
sha3_384: 47997f6556bddb8fb5faa469d6fee29dda4ef811ce3517e7ed874844c814025ca2a7cebad555e0697d2f40e4da1092f8
ep_bytes: e98bddffffcccccccccccccccccccccc
timestamp: 1970-01-01 00:00:00

Version Info:

Comments: Software Appcation
CompanyName: Lenovo
FileDescription: Files Menager
FileVersion: v1.0.0.1
InternalName: Menager
LegalCopyright: Copyright (c) 2021 GUCII
OriginalFilename: Menager.exe
ProductName: Menager
ProductVersion: v1.0.0.1
Translation: 0x0804 0x04b0

Trojan:Win32/Znyonm also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKDZ.103904
FireEyeTrojan.GenericKDZ.103904
ALYacTrojan.GenericKDZ.103904
VIPRETrojan.GenericKDZ.103904
SangforTrojan.Win32.Silverfox.ulgyzg
K7AntiVirusTrojan ( 005ad5f41 )
BitDefenderTrojan.GenericKDZ.103904
K7GWTrojan ( 005ad5f41 )
Cybereasonmalicious.56bc5a
BitDefenderThetaGen:NN.ZexaF.36792.@F3@aKCeJeoi
ESET-NOD32a variant of WinGo/TrojanDropper.Agent.CN
APEXMalicious
KasperskyBackdoor.Win32.Lotok.sfa
AlibabaBackdoor:Win32/Lotok.e40d005f
RisingBackdoor.Agent!1.ECF5 (CLASSIC)
F-SecureTrojan.TR/Redcap.xqdgd
ZillyaBackdoor.Lotok.Win32.3599
TrendMicroTROJ_GEN.R011C0XKC23
EmsisoftTrojan.GenericKDZ.103904 (B)
IkarusTrojan-Dropper.WinGo.Agent
JiangminTrojan.Generic.hrstq
AviraTR/Redcap.xqdgd
Antiy-AVLTrojan[Backdoor]/Win32.Lotok
MicrosoftTrojan:Win32/Znyonm
ArcabitTrojan.Generic.D195E0
ZoneAlarmBackdoor.Win32.Lotok.sfa
GDataTrojan.GenericKDZ.103904
CynetMalicious (score: 99)
AhnLab-V3Malware/Win.Malware-gen.R619258
MAXmalware (ai score=85)
TrendMicro-HouseCallTROJ_GEN.R011C0XKC23
TencentTrojan.Win32.Agent_yh.16001067
MaxSecureTrojan.Malware.220002475.susgen
FortinetW32/Agent.CN!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Znyonm?

Trojan:Win32/Znyonm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment