Spy

What is “Spyware.SnakeKeylogger.AutoIt”?

Malware Removal

The Spyware.SnakeKeylogger.AutoIt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.SnakeKeylogger.AutoIt virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the Snake malware family

How to determine Spyware.SnakeKeylogger.AutoIt?


File Info:

name: F77ACC75E759F597C9B7.mlw
path: /opt/CAPEv2/storage/binaries/46490ab098719933edbd19f9d6ab0d4ac6b89c8eba39705dac5c9e134529baa1
crc32: 91D70354
md5: f77acc75e759f597c9b7dcac4fb847d0
sha1: 09b7e6c4dd8ec5b53b9e99253c8ddd8925fbcc7e
sha256: 46490ab098719933edbd19f9d6ab0d4ac6b89c8eba39705dac5c9e134529baa1
sha512: 039b44b17b9d42a6cbe110f96523b1443d39106c4f93127c0c5cc0e5a0b5655b3bbaa9a94b635e0911d9f6038c3f58aabca6cc3b5c4ad1c00e39ab3c8e3e3822
ssdeep: 24576:y4lavt0LkLL9IMixoEFNYuaT3/ArbnC84+lcwVq9MmCS:lkwkn9IMSNYuaz/AvnCH+FaPCS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10955D043B79D82D8D37251337A52B741AEBB7C2902A1B1AB3FCD453DE960261421FE63
sha3_384: c90ef3a7d1bdba6ca032534c4ee0a667d771b2cd61fb49d2a3c13d7dbe2e42b92fc3efe02810a6a0c421135ac3707dcb
ep_bytes: e897cf0000e97ffeffffcccccccccccc
timestamp: 2021-09-01 12:33:57

Version Info:

Translation: 0x0809 0x04b0

Spyware.SnakeKeylogger.AutoIt also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.KillProc.48407
MicroWorld-eScanAIT:Trojan.Nymeria.4918
ALYacAIT:Trojan.Nymeria.4918
MalwarebytesSpyware.SnakeKeylogger.AutoIt
CrowdStrikewin/malicious_confidence_90% (D)
SymantecAUT.Heuristic!gen16
ESET-NOD32a variant of Win32/Injector.Autoit.FMG
APEXMalicious
KasperskyVHO:Trojan-PSW.MSIL.Agensla.gen
BitDefenderAIT:Trojan.Nymeria.4918
AvastAutoIt:Obfuscated-F [Cryp]
Ad-AwareAIT:Trojan.Nymeria.4918
SophosML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.f77acc75e759f597
EmsisoftAIT:Trojan.Nymeria.4918 (B)
IkarusTrojan.Autoit
AviraHEUR/AGEN.1207741
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitAIT:Trojan.Nymeria.D1336
GDataAIT:Trojan.Nymeria.4918 (2x)
CynetMalicious (score: 100)
Acronissuspicious
McAfeeDropper-AutoIt.s
MAXmalware (ai score=83)
CylanceUnsafe
eGambitUnsafe.AI_Score_99%
FortinetAutoIt/Agent.DCCC!tr
AVGAutoIt:Obfuscated-F [Cryp]
Cybereasonmalicious.4dd8ec

How to remove Spyware.SnakeKeylogger.AutoIt?

Spyware.SnakeKeylogger.AutoIt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment