Trojan

Trojan:Win32/Znyonm malicious file

Malware Removal

The Trojan:Win32/Znyonm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Znyonm virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Znyonm?


File Info:

name: A0CFE68898ADE6AB5271.mlw
path: /opt/CAPEv2/storage/binaries/f4f6eddf3bdb459a0949318cd623e487c9c41c460f2fdd9086bd62e1429e6355
crc32: AE7142D3
md5: a0cfe68898ade6ab527126950111d52c
sha1: 7cc4e1e4e2db3b88ec19c754dd3bb5f9da7aedb0
sha256: f4f6eddf3bdb459a0949318cd623e487c9c41c460f2fdd9086bd62e1429e6355
sha512: 77d5cfdfd681c256e20760209ecb9d1977cf6414aa6d96a2c7a8288390fa5e09e78e0f3e1c0f6cba1569acdc065bf2f378f5d9880c81a9724141912628022643
ssdeep: 12288:bqxXipAXQt+VurKWvTJt5hal/3qafsCcUNdDB+Medup9+Gfkth:O51Qt+VurKWvyl/3qudcmdDDS/t
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ADE4F150B0B250B0CCA7607045AEB57B59ED9C250F2E87C38770AF56ED70EDA363A789
sha3_384: 55927dcca79ac76a49b56be37610d59de15976db3d0de4051faebfb5e00cb86b0741aed3332e7b1c0071b8fdada2f8f4
ep_bytes: 60be002049008dbe00f0f6ff57eb0b90
timestamp: 2021-07-06 19:53:57

Version Info:

FileVersion: 1.0.0.0
Comments: MPV Installer
FileDescription: MPV Installer
ProductVersion: 3.3.14.2
LegalCopyright: Copyright © Sally 2021
Translation: 0x0404 0x04b0

Trojan:Win32/Znyonm also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Autoit.4!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.70160827
FireEyeGeneric.mg.a0cfe68898ade6ab
CAT-QuickHealTrojan.Znyonm
SkyhighBehavesLike.Win32.TrojanAitInject.jc
McAfeeArtemis!A0CFE68898AD
Cylanceunsafe
VIPRETrojan.GenericKD.70160827
SangforTrojan.Win32.Autoit.Vwre
K7AntiVirusTrojan ( 0040be531 )
AlibabaTrojan:AutoIt/Injector.f5566a94
K7GWTrojan ( 0040be531 )
Cybereasonmalicious.4e2db3
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.Autoit.FO
CynetMalicious (score: 100)
APEXMalicious
BitDefenderTrojan.GenericKD.70160827
AvastWin32:Trojan-gen
TencentAutoit.Trojan.Autoit.Mcnw
SophosMal/Generic-S
F-SecureTrojan.TR/AutoIt.mbmei
ZillyaTrojan.Injector.Win32.1721581
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.70160827 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/AutoIt.mbmei
Antiy-AVLGrayWare/MSIL.Kryptik.eve
KingsoftWin32.Troj.Undef.a
MicrosoftTrojan:Win32/Znyonm
ArcabitTrojan.Generic.D42E91BB
GDataTrojan.GenericKD.70160827
GoogleDetected
ALYacTrojan.GenericKD.70160827
MAXmalware (ai score=84)
VBA32Trojan.Autoit.Wirus
MalwarebytesMalware.AI.1710946292
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H09KF23
RisingTrojan.Injector!8.C4 (CLOUD)
YandexTrojan.Injector!G3CXSHO0M/c
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.220427424.susgen
FortinetW32/Injector_Autoit.FO!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan:Win32/Znyonm?

Trojan:Win32/Znyonm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment