Backdoor

Backdoor.Win32.Androm.snfq malicious file

Malware Removal

The Backdoor.Win32.Androm.snfq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.snfq virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • CAPE detected the AgentTesla malware family
  • Creates known CypherIT/Frenchy Shellcode mutexes
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Androm.snfq?


File Info:

name: 0E3D64096F0D53B5FC33.mlw
path: /opt/CAPEv2/storage/binaries/bd8779b74e12db727a6bc718da85c37a07e6e0e988a0aef8c1e0dbaaba9a72ae
crc32: AD090382
md5: 0e3d64096f0d53b5fc33923875671b80
sha1: 54de7afe3ffac89fc455eeeb42ba1744c90433c1
sha256: bd8779b74e12db727a6bc718da85c37a07e6e0e988a0aef8c1e0dbaaba9a72ae
sha512: 4dcade13af1b448a174755db1066f8dc61bd06abc4c49fef63b309dbd1208cc7ef5264e5f00c6cf51bca681a00a664ba477a881642663c9d288a18760495fc01
ssdeep: 24576:tAHnh+eWsN3skA4RV1Hom2KXFmIaKrQCoyBMTpz05:Mh+ZkldoPK1XaKrLSp2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EB459C0263939025FEAE92735B55B201D6BC69293123CCFF12B81D79B9731A11F2D26F
sha3_384: 3e7b1c479322ab9e3c4c5f761c777aaca98161ba7790261a9f963add16b484a29eba6aa96602801b1dd32e84e713a5a7
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2019-06-09 10:31:58

Version Info:

FileDescription: LegacyNetUXHost
OriginalFilename: AuthBroker
CompanyName: DeviceEject
FileVersion: 758.32.220.314
LegalCopyright: ActionMgr
ProductName: appvetwstreamingux
ProductVersion: 348.32.155.410
Translation: 0x0409 0x04b0

Backdoor.Win32.Androm.snfq also known as:

BkavW32.AIDetect.malware1
LionicHacktool.Win32.Gamehack.3!e
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.41360968
FireEyeGeneric.mg.0e3d64096f0d53b5
CAT-QuickHealTrojan.AgentSM.S6640043
McAfeeGeneric.btq
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/AutoitCrypt.180
K7GWSpyware ( 004bf6371 )
K7AntiVirusSpyware ( 004bf6371 )
BitDefenderThetaAI:Packer.3DDD251317
VirITTrojan.Win32.AutoIt.BMO
CyrenW32/AutoIt.QF.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32MSIL/Spy.Agent.AES
TrendMicro-HouseCallTrojan.AutoIt.CRYPTINJECT.SMA
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Androm.snfq
BitDefenderTrojan.GenericKD.41360968
NANO-AntivirusTrojan.Win32.Androm.frkdhk
ViRobotTrojan.Win32.S.Agent.1181184.C
APEXMalicious
TencentWin32.Backdoor.Androm.Glx
SophosMal/Generic-S + Troj/Autoit-CMS
ComodoMalware@#2ihu9sz3mxxbk
DrWebTrojan.MulDrop9.13190
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.AutoIt.CRYPTINJECT.SMA
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
EmsisoftTrojan.GenericKD.41360968 (B)
IkarusTrojan.MSIL.Spy
AviraBDS/Spy.Agent.C
Antiy-AVLTrojan/Generic.ASCommon.15F
MicrosoftTrojan:Win32/Skeeyah.A!MTB
ZoneAlarmBackdoor.Win32.Androm.snfq
GDataWin32.Trojan.Agent.5KV3BF
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Autoinj03.Exp
ALYacSpyware.AgentTesla
TACHYONTrojan/W32.Agent.1181184.C
VBA32Trojan-Downloader.Autoit.gen
MalwarebytesMachineLearning/Anomalous.95%
AvastAutoIt:Injector-JM [Trj]
RisingTrojan.Injector/Autoit!1.BB82 (CLASSIC)
eGambitUnsafe.AI_Score_90%
FortinetW32/Agent.AES!tr
AVGAutoIt:Injector-JM [Trj]
Cybereasonmalicious.96f0d5
PandaTrj/WLT.E

How to remove Backdoor.Win32.Androm.snfq?

Backdoor.Win32.Androm.snfq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment