Trojan

Trojan:Win32/Znyonm removal instruction

Malware Removal

The Trojan:Win32/Znyonm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Znyonm virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Znyonm?


File Info:

name: 6C6425C6A78CFEAF4578.mlw
path: /opt/CAPEv2/storage/binaries/f47ae214c39ce14112351b7fa2b5c4f06c98578d72fe32b22f098fe086cae1c0
crc32: 8B105700
md5: 6c6425c6a78cfeaf4578cdc22bbb8c65
sha1: 0b51ed86fba58dfa0f40963e818447e65305a273
sha256: f47ae214c39ce14112351b7fa2b5c4f06c98578d72fe32b22f098fe086cae1c0
sha512: 7d2651cf410c20861c958d8ac897e22c7248452b0d2835e79f4e848e735f2bdf462ed27f34fe0d26213ffe7b748d7f0298c7db4fe992199cb61d11bdfaa0ec61
ssdeep: 24576:qqbNRqZjLGQ25kd28ncx53vEeLu0aik/c:xRqZjLGQgk0sqhvJai
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11805234D79ECF47DDC1847B592A739000B07AD0A06B9D46E316B320A7BFE26E65237B1
sha3_384: ce9c81ab46ee2d5eec3b5d2353f39293a76a2458a54ce55f7968ed87fe3009bed0ea8bb40c31e3382344ff3ed6815e1f
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-12-07 10:29:35

Version Info:

Translation: 0x0000 0x04b0
Comments: 天之蓝软件工作室
CompanyName: 一款优秀的英语单词记忆软件!
FileDescription: 不想背单词
FileVersion: 9.3.0.0
InternalName: 不想背单词.exe
LegalCopyright: Copyright © 赵晋 个人所有
OriginalFilename: 不想背单词.exe
ProductName: 不想背单词
ProductVersion: 9.3.0.0
Assembly Version: 9.3.0.0

Trojan:Win32/Znyonm also known as:

BkavW32.Common.88D16E2B
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.70710565
SkyhighArtemis!Trojan
McAfeeArtemis!6C6425C6A78C
Cylanceunsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWRiskware ( 00584baa1 )
K7AntiVirusRiskware ( 00584baa1 )
ArcabitTrojan.Generic.D436F525
BitDefenderThetaGen:NN.ZemsilF.36680.0m0@aKJfkhi
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKD.70710565
SophosMal/Generic-S
VIPRETrojan.GenericKD.70710565
EmsisoftTrojan.GenericKD.70710565 (B)
GoogleDetected
Antiy-AVLTrojan/Win32.Znyonm
Kingsoftmalware.kb.c.999
MicrosoftTrojan:Win32/Znyonm
GDataTrojan.GenericKD.70710565
VaristW32/ABRisk.WOEU-4514
AhnLab-V3Trojan/Win.Generic.R502700
VBA32CIL.HeapOverride.Heur
ALYacTrojan.GenericKD.70710565
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R002H09LD23
RisingMalware.Obfus/MSIL@AI.88 (RDM.MSIL2:/a74TPMg4Omm1gATNpfQVw)
SentinelOneStatic AI – Malicious PE
FortinetPossibleThreat
Cybereasonmalicious.6fba58
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Znyonm?

Trojan:Win32/Znyonm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment