In this post, I am going to explain how the Tonmye trojan injected right into your personal computer, and also how to get rid of Tonmye trojan virus.
What is Tonmye trojan?
Name | Tonmye |
Infection Type | Trojan |
Symptoms |
|
Similar behavior | Obfuscated, Witproc, Ligzoc, Togapy, Xtrat, Pher |
Fix Tool | See If Your System Has Been Affected by Tonmye trojan |
Trojan viruses are among the leading malware types by its injection rate for quite a long time. And currently, during the pandemic, when malware became extremely active, trojan viruses raised their activity, too. You can see lots of messages on various sources, where users are complaining concerning the Tonmye trojan virus in their computers, and asking for help with Tonmye trojan virus elimination.
Trojan Tonmye is a sort of virus that injects right into your personal computer, and afterwards executes various malicious features. These features depend on a type of Tonmye trojan: it might serve as a downloader for many other malware or as a launcher for another destructive program which is downloaded in addition to the Tonmye trojan. During the last 2 years, trojans are also distributed through e-mail add-ons, and in the majority of cases used for phishing or ransomware infiltration.
Tonmye2 also known as
Bkav | W32.AIDetectVM.malware1 |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Gen:Variant.Zusy.313066 |
FireEye | Generic.mg.f9b13bba9c3e4a82 |
CAT-QuickHeal | Trojan.Hebchengjiu |
McAfee | Artemis!F9B13BBA9C3E |
Cylance | Unsafe |
Zillya | Adware.Hebchengjiu.Win32.40 |
AegisLab | Adware.Win32.Generic.2!c |
Sangfor | Malware |
K7AntiVirus | Trojan ( 005246d51 ) |
BitDefender | Gen:Variant.Zusy.313066 |
K7GW | Trojan ( 005246d51 ) |
Cybereason | malicious.a9c3e4 |
Cyren | W32/S-ccde6294!Eldorado |
Symantec | ML.Attribute.HighConfidence |
APEX | Malicious |
Avast | Win32:Adware-gen [Adw] |
ClamAV | Win.Malware.Mikey-6718286-0 |
Kaspersky | not-a-virus:HEUR:AdWare.Win32.Generic |
NANO-Antivirus | Riskware.Win32.FlyStudio.egmhfc |
Tencent | Win32.Trojan.Strictor.Efuf |
Ad-Aware | Gen:Variant.Zusy.313066 |
Sophos | Generic PUA CA (PUA) |
Comodo | Worm.Win32.Dropper.RA@1qraug |
F-Secure | Adware.ADWARE/Hebchengjiu.gva |
DrWeb | Trojan.DownLoader23.31785 |
VIPRE | Trojan.Win32.Generic!BT |
McAfee-GW-Edition | BehavesLike.Win32.Generic.vh |
Emsisoft | Gen:Variant.Zusy.313066 (B) |
Jiangmin | AdWare.Generic.cqdx |
Avira | ADWARE/Hebchengjiu.gva |
Antiy-AVL | RiskWare[RiskTool]/Win32.FlyStudio |
Microsoft | Trojan:Win32/Tonmye |
Arcabit | Trojan.Zusy.D4C6EA |
ZoneAlarm | not-a-virus:HEUR:AdWare.Win32.Generic |
GData | Win32.Application.PUPStudio.B |
Cynet | Malicious (score: 100) |
Acronis | suspicious |
BitDefenderTheta | Gen:NN.ZexaF.34804.ds1@aCgrrrob |
MAX | malware (ai score=85) |
VBA32 | BScope.Trojan.Tiggre |
Malwarebytes | Generic.Trojan.Malicious.DDS |
Panda | Trj/Genetic.gen |
ESET-NOD32 | a variant of Win32/Adware.Hebchengjiu.A |
Rising | Trojan.ClickDouTu!1.A668 (CLASSIC) |
Yandex | Trojan.GenAsa!SP0Z+34MNu4 |
SentinelOne | Static AI – Malicious PE – Adware |
eGambit | Unsafe.AI_Score_99% |
Fortinet | Adware/Generic |
AVG | Win32:Adware-gen [Adw] |
Paloalto | generic.ml |
CrowdStrike | win/malicious_confidence_100% (D) |
Qihoo-360 | Win32/Virus.Adware.b51 |
Domains that associated with Tonmye:
0 | hao.360.cn |
What are the symptoms of Tonmye trojan?
- Attempts to connect to a dead IP:Port (1 unique times);
- A process attempted to delay the analysis task.;
- Reads data out of its own binary image;
- Drops a binary and executes it;
- Unconventionial binary language: Chinese (Simplified);
- Unconventionial language used in binary resources: Chinese (Simplified);
- Queries information on disks, possibly for anti-virtualization;
- Attempts to modify proxy settings;
- Attempts to modify browser security settings;
The usual signs and symptom of the Tonmye trojan virus is a gradual appearance of different malware – adware, browser hijackers, et cetera. Due to the activity of these destructive programs, your personal computer comes to be very lagging: malware absorbs big quantities of RAM and CPU abilities.
Another detectable effect of the Tonmye trojan virus visibility is unidentified operations showed in task manager. Frequently, these processes may attempt to mimic system processes, but you can understand that they are not legit by taking a look at the origin of these tasks. Pseudo system applications and Tonmye trojan’s processes are always specified as a user’s tasks, not as a system’s.
How to remove Tonmye trojan virus?
- Download and install Loaris Trojan Remover.
- Open Loaris and perform a “Standard scan“.
- “Move to quarantine” all items.
- Open “Tools” tab – Press “Reset Browser Settings“.
- Approve the reset pressing “Yes” button in the appeared window.
- Restart your computer.
To clean up Tonmye trojan and also be sure that all satellite malware, downloaded with the help of this trojan, will be eliminated, as well, I’d advise you to use Loaris Trojan Remover.
Tonmye removal guide
To spot and delete all viruses on your PC using Loaris, it’s better to make use of Standard or Full scan. Removable scan, as well as Custom, will scan only specified folders, so such scans cannot provide the full information.
You can spectate the detects during the scan process lasts. Nonetheless, to execute any actions against detected malicious programs, you need to wait until the process is over, or to stop the scan.
To choose the appropriate action for each detected viruses, choose the button in front of the detection name of detected viruses. By default, all viruses will be sent to quarantine.
How to remove Tonmye Trojan?
Name: Tonmye
Description: Trojan Tonmye is a kind of virus that infiltrates into your computer, and after that performs different destructive functions. These features depend upon a type of Tonmye trojan: it can act as a downloader for many other malware or as a launcher for another destructive program which is downloaded in addition to the Tonmye trojan. During the last two years, trojans are also dispersed via e-mail attachments, and most of situations utilized for phishing or ransomware infiltration.
Operating System: Windows
Application Category: Trojan