Backdoor

Generic.Backdoor.ShadowBrokers.A3B68A18 (file analysis)

Malware Removal

The Generic.Backdoor.ShadowBrokers.A3B68A18 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Backdoor.ShadowBrokers.A3B68A18 virus can do?

  • Executable code extraction
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

api.nuget.org

How to determine Generic.Backdoor.ShadowBrokers.A3B68A18?


File Info:

crc32: 6673B58A
md5: 3771b97552810a0ed107730b718f6fe1
name: 64442cceb7d618e70c62d461cfaafdb8e653b8d98ac4765a6b3d8fd1ea3bce15
sha1: f57f71ae1e52f25ec9f643760551e1b6cfb9c7ff
sha256: 64442cceb7d618e70c62d461cfaafdb8e653b8d98ac4765a6b3d8fd1ea3bce15
sha512: b6a18449b145749d57297b91d6f6114d974b3665ffc9d8ab001e349cc9f64c6df982a0fee619f0fa8b7892bfc7e29956bd9fbe28c5f13f1e0431f4ac32d47b63
ssdeep: 6144:TztgTcIX6E+QQMl6CnvXj7e9KOoFRJyFOwt3eN6qWZGTeeLhznw/wHJRGHUQBaB:Tz6TcOGQQMlf6iFRJyFOy3eUqWZGKeL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: required
FileVersion: 1.00
CompanyName: Microsoft
ProductName: Project1
ProductVersion: 1.00
OriginalFilename: required.exe

Generic.Backdoor.ShadowBrokers.A3B68A18 also known as:

BkavW32.LesturosDJQ.Trojan
MicroWorld-eScanGeneric.Backdoor.ShadowBrokers.A3B68A18
FireEyeGeneric.mg.3771b97552810a0e
CAT-QuickHealTrojan.EternalRock.A3
Qihoo-360HEUR/QVM41.2.151E.Malware.Gen
ALYacWorm.EternalRocks
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusEmailWorm ( 004c16271 )
BitDefenderGeneric.Backdoor.ShadowBrokers.A3B68A18
K7GWEmailWorm ( 004c16271 )
Cybereasonmalicious.552810
Invinceaheuristic
BitDefenderThetaAI:Packer.2BFFE07227
CyrenW32/Trojan.YSBZ-4482
BaiduWin32.Trojan.EternalRocks.c
TrendMicro-HouseCallTROJ_ETEROCK.A
Paloaltogeneric.ml
ClamAVWin.Trojan.EternalRocks1-6319293-0
GDataGeneric.Backdoor.ShadowBrokers.A3B68A18
KasperskyTrojan.Win32.Reconyc.hxyl
AlibabaTrojanDownloader:Win32/Reconyc.b577353e
NANO-AntivirusTrojan.Win32.Fsysna.eotiow
ViRobotTrojan.Win32.Agent.346112.Q
TencentWin32.Trojan.Bluedoom.Auto
Ad-AwareGeneric.Backdoor.ShadowBrokers.A3B68A18
SophosTroj/Eterocks-B
ComodoTrojWare.Win32.TrojanDownloader.VB.PMEA@4rev5s
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader24.59727
ZillyaWorm.Agent.Win32.42807
TrendMicroTROJ_ETEROCK.A
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
SentinelOneDFI – Malicious PE
Trapminemalicious.high.ml.score
CMCTrojan.Win32.Reconyc!O
EmsisoftGeneric.Backdoor.ShadowBrokers.A3B68A18 (B)
APEXMalicious
JiangminWorm.EternalRocks.e
WebrootTrojan.Dropper.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Fsysna
Endgamemalicious (high confidence)
ArcabitGeneric.Backdoor.ShadowBrokers.A3B68A18
AegisLabTrojan.Win32.Reconyc.4!c
ZoneAlarmTrojan.Win32.Reconyc.hxyl
MicrosoftTrojanDownloader:Win32/Eterock.A
TACHYONTrojan/W32.VB-Reconyc.344064
AhnLab-V3Trojan/Win32.Eterock.R201027
Acronissuspicious
McAfeeGenericRXBO-IA!3771B9755281
MAXmalware (ai score=100)
VBA32Trojan.Reconyc
MalwarebytesWorm.EternalRocks
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/TrojanDownloader.VB.RCY
RisingWorm.EternalRocks-01!1.AAFE (KTSE)
YandexTrojan.Reconyc!
IkarusWorm.DoomsDay
eGambitTrojan.Generic
FortinetW32/Eterocks.B!tr
AVGWin32:EternalRocks-E [Trj]
AvastWin32:EternalRocks-E [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.10881605.susgen

How to remove Generic.Backdoor.ShadowBrokers.A3B68A18?

Generic.Backdoor.ShadowBrokers.A3B68A18 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment