Trojan

Trojan:Win32/Znyonm malicious file

Malware Removal

The Trojan:Win32/Znyonm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Znyonm virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Znyonm?


File Info:

name: 42F24355C9161314A354.mlw
path: /opt/CAPEv2/storage/binaries/cdb225c8998e9fbdcf3b1c3910dc5ff22c953f620f160b5cd37ecebf4273a99e
crc32: FA2FEC61
md5: 42f24355c9161314a3547e5bbb874712
sha1: 97533628686a9b0b8265bd43a1320bb528f14701
sha256: cdb225c8998e9fbdcf3b1c3910dc5ff22c953f620f160b5cd37ecebf4273a99e
sha512: 73e8b8c54128c1bde736a7bfb80ed6d0b7049f5cb22b9d1cb614f15a6400cf11cb54a563b00cabe42bc56901ec24a3e124315ab0fdfc5461e9b5cf6077d31729
ssdeep: 24576:Ov3iu12w/PwqZM7u1Vw4a9sAqRDdOAZT:OZwju13jRDJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13C356C12B791C4B2C215153015BA57BEA9309B673A21DEC7B3D4DEAC6C233D1AE2724F
sha3_384: c9aa2e60ec6a4d1feac99cb981af3935e1f269d7b451a4e101e3089e345b8bc8e587e97a2008445d81ed69a42f1946c0
ep_bytes: 558bec6aff68d8434c00686439490064
timestamp: 2023-11-04 14:26:46

Version Info:

0: [No Data]

Trojan:Win32/Znyonm also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lwTm
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.60284
FireEyeGeneric.mg.42f24355c9161314
SkyhighBehavesLike.Win32.Generic.th
ALYacGen:Variant.Babar.60284
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Babar.60284
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
BitDefenderGen:Variant.Babar.60284
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.8686a9
BitDefenderThetaGen:NN.ZexaF.36792.grW@a8aCxLob
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
KasperskyUDS:Trojan.Win64.Agentb.bgp
AlibabaTrojan:Win32/Genric.a2b03a68
NANO-AntivirusTrojan.Win32.FlyStudio.kdedrd
SophosGeneric Reputation PUA (PUA)
DrWebTrojan.Siggen7.35352
TrendMicroTROJ_GEN.R011C0PK623
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Babar.60284 (B)
IkarusTrojan.Win32.Agent
MAXmalware (ai score=86)
GDataWin32.Trojan.PSE.15EXSUN
GoogleDetected
VaristW32/Trojan.CLL.gen!Eldorado
Antiy-AVLTrojan/Win32.FlyStudio.a
Kingsoftmalware.kb.a.953
XcitiumWorm.Win32.Dropper.RA@1qraug
ArcabitTrojan.Babar.DEB7C
ZoneAlarmUDS:Trojan.Win64.Agentb.bgp
MicrosoftTrojan:Win32/Znyonm
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5538197
McAfeeGenericRXET-MT!42F24355C916
DeepInstinctMALICIOUS
VBA32Adware.Presenoker
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R011C0PK623
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.PHP!tr
AVGWin64:Malware-gen
AvastWin64:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan:Win32/Znyonm?

Trojan:Win32/Znyonm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment