Malware

SNH:Script [Dropper] removal tips

Malware Removal

The SNH:Script [Dropper] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What SNH:Script [Dropper] virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine SNH:Script [Dropper]?


File Info:

crc32: EAD53A91
md5: 755f3421340fe5aa1cfbfeb19e6d312c
name: samgood.exe
sha1: d6c5e2d6b46921368d3810a6f851783b891793a2
sha256: f0161c9b13e61bc5e65d08558e265c44b6459be5a5f634539fe6349b7ff69404
sha512: 557bedf7cb4105289e4ffa458860b56b3c9b2478aec2c94176fe495fa29c575e83213d42e7c6f54499769a29dbc5a70556511dc816359af7fc5c81010d4afafe
ssdeep: 49152:zu0c++OCvkGs9FaB47kG6K005SB/p1MY:SB3vkJ9H7kG6K7QBhW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: timeout
CompanyName: WUDFCompanionHost
ProductName: catsrvps
ProductVersion: 803, 40, 423, 432
FileDescription: colorcpl
OriginalFilename: ksetup.exe
Translation: 0x0000 0x04b0

SNH:Script [Dropper] also known as:

MicroWorld-eScanTrojan.AutoIT.Agent.AAJ
McAfeeArtemis!755F3421340F
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 700000111 )
BitDefenderTrojan.AutoIT.Agent.AAJ
K7GWTrojan ( 700000111 )
Cybereasonmalicious.6b4692
Invinceaheuristic
F-ProtW32/AutoIt.NS.gen!Eldorado
APEXMalicious
AvastSNH:Script [Dropper]
GDataTrojan.AutoIT.Agent.AAJ
KasperskyTrojan-Dropper.Win32.Autit.nup
AlibabaTrojan:Win32/AutoitU.ali2000008
AegisLabTrojan.Win32.Autit.b!c
RisingTrojan.Obfus/Autoit!1.C045 (CLASSIC)
Endgamemalicious (high confidence)
EmsisoftTrojan.AutoIT.Agent.AAJ (B)
F-SecureTrojan.TR/Autoit.halnq
DrWebTrojan.AutoIt.737
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
MaxSecureTrojan.Malware.300983.susgen
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.Autoit
CyrenW32/AutoIt.NS.gen!Eldorado
AviraTR/Autoit.halnq
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.AutoIT.Agent.AAJ
ZoneAlarmTrojan-Dropper.Win32.Autit.nup
AhnLab-V3Trojan/Win32.AutoInj.R279467
MalwarebytesTrojan.MalPack.AutoIt
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Injector.Autoit.FCH
TencentWin32.Trojan-dropper.Autit.Aglj
FortinetAutoIt/Injector.FCH!tr
AVGSNH:Script [Dropper]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)

How to remove SNH:Script [Dropper]?

SNH:Script [Dropper] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment