Trojan

Trojan:Win32/Znyonm removal

Malware Removal

The Trojan:Win32/Znyonm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Znyonm virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Znyonm?


File Info:

name: F66A60D7127F53AEC4B6.mlw
path: /opt/CAPEv2/storage/binaries/b1305f51ef814eb302f3825394e64e51e414b7a5062738ece92dd82fd3f205d3
crc32: DDF56738
md5: f66a60d7127f53aec4b63b1e62772510
sha1: 64d9a6a74851645b606de4449142f525551cac70
sha256: b1305f51ef814eb302f3825394e64e51e414b7a5062738ece92dd82fd3f205d3
sha512: c74e7cbe916d4fbe673a7c167e631b72c9327549f0dc5cbee8d560376d147855c333bf2a699a86a079cefd3b32934db057ea7399dfb45a733530a7b5f855b4c3
ssdeep: 98304:bZR7+Mk8o6Y1BagEaERYzUBMV7fjXR+AVppbg5fW+7HnTIn/54PF5Xh9swH/8S/J:b9nP+MUcMVjRnRYvehij1/z
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1CB2633AB4493B8B8F4C22E31532EF9D58A55A8434E4935724C07CDE9853E6C3D7E7A07
sha3_384: 92a6917aa373a882f51b5bd3354e4347b8886c1ee4fdef9daff2c2c6eca6192c6b06aa9e2709efda2371f9208efce62d
ep_bytes: 60be158062008dbeeb8fddff5783cdff
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Znyonm also known as:

CyrenCloudW32/ABRisk.MISJ-5937:51:100:105.B1305F51!Threatlookup
BkavW32.AIDetectMalware
LionicTrojan.Win32.GenCBL.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.MSIL.Krypt.!cdmip!.2
FireEyeGeneric.mg.f66a60d7127f53ae
SkyhighArtemis!Trojan
McAfeeArtemis!F66A60D7127F
Cylanceunsafe
ZillyaDropper.Krypt.Win32.322
K7GWTrojan ( 0058f7d21 )
K7AntiVirusTrojan ( 0058f7d21 )
ArcabitTrojan.MSIL.Krypt.!cdmip!.2
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenCBL.BUN
CynetMalicious (score: 99)
BitDefenderGen:Heur.MSIL.Krypt.!cdmip!.2
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.13efedb2
Ad-AwareGen:Heur.MSIL.Krypt.!cdmip!.2
F-SecureTrojan.TR/Dropper.Gen
VIPREGen:Heur.MSIL.Krypt.!cdmip!.2
TrendMicroTROJ_FRS.0NA103IT23
Trapminemalicious.high.ml.score
EmsisoftGen:Heur.MSIL.Krypt.!cdmip!.2 (B)
IkarusTrojan.Win32.Generic
JiangminTrojan.Generic.gvdqj
WebrootW32.Malware.Gen
VaristW32/ABRisk.MISJ-5937
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.GenCBL
KingsoftWin32.Troj.Generic.v
MicrosoftTrojan:Win32/Znyonm
GDataGen:Heur.MSIL.Krypt.!cdmip!.2
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5490210
ALYacGen:Heur.MSIL.Krypt.!cdmip!.2
MAXmalware (ai score=85)
VBA32BScope.Trojan.Inject
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_FRS.0NA103IT23
RisingDropper.Dapato!8.2A2 (CLOUD)
MaxSecureTrojan.Malware.218555684.susgen
FortinetW32/GenCBL.BUN!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Znyonm?

Trojan:Win32/Znyonm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment