Trojan

How to remove “Trojan:Win32/Znyonm”?

Malware Removal

The Trojan:Win32/Znyonm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Znyonm virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Trojan:Win32/Znyonm?


File Info:

name: FF485BA7B855EDB37F2B.mlw
path: /opt/CAPEv2/storage/binaries/7491c60b5a7487852d652840b5ae57de498de7a731421d47b72039f8634d55e6
crc32: 7AFCF4C6
md5: ff485ba7b855edb37f2b724d68a7bc9a
sha1: bb8f8c4b1041ef96c276dab01476324dbec57f55
sha256: 7491c60b5a7487852d652840b5ae57de498de7a731421d47b72039f8634d55e6
sha512: 847958e6d0938986d1e13e589ff8671bff7b352112cc71c4dc38ccae882d035ad8f13391301c3badb9be5be16abb4559de7948fc64f7577ff3dd6e3f449c6086
ssdeep: 24576:mtF5TWrTZrtYbfcR2YfUpxrKl0XinWMCyFC:mtFd8bYbfs2XpklwinFw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FC25239123F95FA6EA7943F93065424173B0BA6FB961DB3E0DC001DD8C61BB1E662B13
sha3_384: 25a357a2ddeac96e5b9b6d0bd7b4c88c6a7ff9a185c79dc8dd97010cec54ba2d4fbd3cfa4ffac8ed03f190261742026a
ep_bytes: ff250020400000000000000000000000
timestamp: 2094-03-13 20:30:10

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: WindowsFormsApp1
FileVersion: 1.0.0.0
InternalName: WindowsFormsApp1.exe
LegalCopyright: Copyright © 2020
LegalTrademarks:
OriginalFilename: WindowsFormsApp1.exe
ProductName: WindowsFormsApp1
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:Win32/Znyonm also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Agensla.i!c
Elasticmalicious (moderate confidence)
DrWebTrojan.Packed2.46200
MicroWorld-eScanTrojan.GenericKD.71341228
FireEyeTrojan.GenericKD.71341228
CAT-QuickHealTrojanpws.Msil
SkyhighGenericRXWN-JY!FF485BA7B855
McAfeeGenericRXWN-JY!FF485BA7B855
MalwarebytesTrojan.Downloader
SangforInfostealer.Msil.Kryptik.Vlsn
K7AntiVirusTrojan ( 005b11091 )
AlibabaTrojanPSW:MSIL/Agensla.9aa2d449
K7GWTrojan ( 005b11091 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilF.36744.an0@aqtJe7k
VirITTrojan.Win32.Genus.UZZ
SymantecTrojan Horse
ESET-NOD32a variant of MSIL/Kryptik.AKTC
APEXMalicious
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderTrojan.GenericKD.71341228
NANO-AntivirusTrojan.Win32.Agensla.khufxp
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.13fef4ff
EmsisoftTrojan.GenericKD.71341228 (B)
F-SecureTrojan.TR/Kryptik.twtrq
VIPRETrojan.GenericKD.71341228
TrendMicroTROJ_GEN.R002C0XB124
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
WebrootW32.Malware.Gen
VaristW32/Trojan.OQJD-0714
AviraTR/Kryptik.twtrq
MAXmalware (ai score=85)
Antiy-AVLTrojan[PSW]/MSIL.Agensla
KingsoftWin32.PSWTroj.Undef.a
MicrosoftTrojan:Win32/Znyonm
XcitiumMalware@#26925xl1p5cm9
ArcabitTrojan.Generic.D44094AC
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataTrojan.GenericKD.71341228
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Injection.C5579744
VBA32TScope.Trojan.MSIL
ALYacTrojan.GenericKD.71341228
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0XB124
RisingMalware.Obfus/MSIL@AI.92 (RDM.MSIL2:nAhtpbOl3onCF+j6i/monQ)
IkarusTrojan.MSIL.Krypt
MaxSecureTrojan.Malware.74499699.susgen
FortinetPossibleThreat
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Znyonm?

Trojan:Win32/Znyonm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment