Trojan

About “Trojan:Win32/Znyonm” infection

Malware Removal

The Trojan:Win32/Znyonm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Znyonm virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Znyonm?


File Info:

name: FF75957AAB71A476B2DA.mlw
path: /opt/CAPEv2/storage/binaries/34b4a59fb9c7a46db087cd47c6faecc8b86fc39d34c904337f591f147f67faf0
crc32: CB7629CF
md5: ff75957aab71a476b2dafa4747111e69
sha1: 3963fcada71eb903de18911452b194e3cb3a4261
sha256: 34b4a59fb9c7a46db087cd47c6faecc8b86fc39d34c904337f591f147f67faf0
sha512: 21c945638b934b6236c56b12246e73fa178275014358775a8a2056d02f38774ff3b42717cb0b644296e348451eca958d09e7d69288a1b65be728ec281b907029
ssdeep: 49152:t/+9rOLMM8DNQ8snDm/UWKHNj0es8HGdOwJJhVyHiTyS1x:hYrOLMM2DUm/UW4Nj0qHGzh51x
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11816AE02F6C143B7C507113130BA673BAA7DEE754635DBC7A790FE291C32192A92627E
sha3_384: 8149c0437287bebb0c06fa4a5fbb3b49dd78d8d1ff59ca910293caaa26827c78aea06426a9873c9e118f03ac4fa316bb
ep_bytes: 558bec6aff6820c67e00687037480064
timestamp: 2023-10-13 14:04:47

Version Info:

FileVersion: 5.9.3.0
FileDescription: 易语言破解装置
ProductName: 破解
ProductVersion: 5.9.3.0
CompanyName: Moon
LegalCopyright: 免费软件,请勿用于商业用途
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Trojan:Win32/Znyonm also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.FlyStudio.4!c
Elasticmalicious (high confidence)
ClamAVWin.Malware.Flystudio-6937682-0
SkyhighBehavesLike.Win32.Generic.rh
McAfeeArtemis!FF75957AAB71
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 005246d51 )
K7AntiVirusTrojan ( 005246d51 )
BitDefenderThetaGen:NN.ZexaF.36792.@t0@aiKH1xgb
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.ff75957aab71a476
SophosMal/Generic-S
IkarusTrojan.Win32.Agent
VaristW32/S-480dd005!Eldorado
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumWorm.Win32.Dropper.RA@1qraug
MicrosoftTrojan:Win32/Znyonm
GDataWin32.Trojan.PSE.1GH2WXA
GoogleDetected
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H0CJU23
RisingTrojan.Generic@AI.99 (RDML:GKSkpc90pnOOQQrM207ffQ)
SentinelOneStatic AI – Malicious PE
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.PHP!tr
Cybereasonmalicious.da71eb
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Znyonm?

Trojan:Win32/Znyonm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment