Trojan

Trojan:Win32/Znyonm malicious file

Malware Removal

The Trojan:Win32/Znyonm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Znyonm virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Znyonm?


File Info:

name: 1D7829DB8631F532103B.mlw
path: /opt/CAPEv2/storage/binaries/c12037532267a2d242bdb0bd83c5adb14f1b5192f4e781a53ecaa1d8eb2bcd54
crc32: C6621D5F
md5: 1d7829db8631f532103b9d5fb590f37b
sha1: 52e7f9105212212523fb0fa7489cfda1652c10d1
sha256: c12037532267a2d242bdb0bd83c5adb14f1b5192f4e781a53ecaa1d8eb2bcd54
sha512: 5e63d7dd85ba0117bae62e981fefbdd156eae91e724a048f57c2bd820d49065f939f3f0e282e5fcdb2dcf19da2f0dcc05363adc33d5df87a421d958f6b2f52dc
ssdeep: 98304:3nWi6mMmof5GW0OpDtpDUgdHnQt8uPbFqgw0hi:GfxGM9tpDUgdHnQt8GbRjhi
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1511633E0EF588F44EC38B772E15F672A0825FCBC501AC551EF58B02635A4EA0F59B4B9
sha3_384: 08341d1e663b4dca68dbd8e5858676b19d617f142b7632876bad04e4a18b8708e9886f15eee63ffda21fd50d7630954c
ep_bytes: 807c2408010f85d00b000060be00a056
timestamp: 2023-11-27 16:59:16

Version Info:

FileVersion: 3.7.0.0
FileDescription: 易语言程序
ProductName: 解析插件
ProductVersion: 3.7.0.0
CompanyName: 失去同步
LegalCopyright: 失去同步 版权所有
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Trojan:Win32/Znyonm also known as:

LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
CynetMalicious (score: 100)
FireEyeGeneric.mg.1d7829db8631f532
SkyhighBehavesLike.Win32.Flyagent.rc
McAfeeArtemis!1D7829DB8631
Cylanceunsafe
VIPRETrojan.GenericKD.70618422
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
K7GWAdware ( 005848221 )
K7AntiVirusAdware ( 005848221 )
ArcabitTrojan.Generic.D4358D36
BitDefenderThetaGen:NN.ZedlaF.36680.@pSfaKDYckfH
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
ClamAVWin.Malware.Trojanx-9951053-0
BitDefenderTrojan.GenericKD.70618422
MicroWorld-eScanTrojan.GenericKD.70618422
AvastWin32:TrojanX-gen [Trj]
SophosMal/Generic-S
TrendMicroTROJ_FRS.VSNTLJ23
EmsisoftTrojan.GenericKD.70618422 (B)
IkarusTrojan.Win32.KillAV
VaristW32/ABRisk.RLSY-8018
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.FlyStudio.a
MicrosoftTrojan:Win32/Znyonm
GDataWin32.Trojan.PSE.1KQMTX4
GoogleDetected
AhnLab-V3Malware/Win.Generic.R573454
ALYacTrojan.GenericKD.70618422
MalwarebytesMalware.AI.4155926400
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_FRS.VSNTLJ23
RisingTrojan.Znyonm!8.18A3A (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureDropper.Dinwod.frindll
FortinetRiskware/Application
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Znyonm?

Trojan:Win32/Znyonm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment