Trojan

Trojan:Win32/Znyonm removal instruction

Malware Removal

The Trojan:Win32/Znyonm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Znyonm virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Znyonm?


File Info:

name: DF6B01C3F3FC0885874E.mlw
path: /opt/CAPEv2/storage/binaries/f321eec358959ba20011ddb8be20510cba9c8211c4508945b3713ab115b48320
crc32: 836D2C69
md5: df6b01c3f3fc0885874e1c4886b40850
sha1: 2b88cf79f8974692df4a19333e234cc40a0ac1a9
sha256: f321eec358959ba20011ddb8be20510cba9c8211c4508945b3713ab115b48320
sha512: 4e3d7a5b44f70fc205f3a238cc8b94482025f53a632e52c8014db21a2410233cd92b0e94138328277f7e45756baf1f9e0684c911cb47971e00d89920c746dfb9
ssdeep: 98304:u/5i0bC9qUcIdTo1pmRiGOcYMJAjAk4ZnUC/viHLbpgZiFjpbpgZiFj:uhriBe1p0iGOWGV43ZiRUZiR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F2969DA3B242663EC06F7A365423A6169D3BEF51658B8C0B57F1788CDF354843A3A347
sha3_384: 3985bdad784c12e2197dfda549ae87c57b140a6873a1973778d95aa3c40c72055871453f8ed6d43738398b7cc5a4c86f
ep_bytes: 558bec83c4f0b844596300e8582dddff
timestamp: 2023-12-06 03:51:26

Version Info:

FileDescription: reg
FileVersion: 1.0.0.0
ProgramID: com.embarcadero.reg
ProductName: reg
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04e4

Trojan:Win32/Znyonm also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Znyonm.4!c
FireEyeGeneric.mg.df6b01c3f3fc0885
CAT-QuickHealTrojan.Znyonm
SkyhighBehavesLike.Win32.Generic.rh
SangforTrojan.Win32.Znyonm.Vu8o
Cybereasonmalicious.9f8974
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 100)
AvastWin32:TrojanX-gen [Trj]
Trapminemalicious.moderate.ml.score
Antiy-AVLTrojan/Win32.PossibleThreat
MicrosoftTrojan:Win32/Znyonm
VaristW32/ABRisk.BQCN-2423
MalwarebytesTrojan.Injector
PandaTrj/Chgt.AD
RisingTrojan.Znyonm!8.18A3A (CLOUD)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Znyonm?

Trojan:Win32/Znyonm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment