Trojan

How to remove “TrojanDownloader:Win32/Snojan.BB!MTB”?

Malware Removal

The TrojanDownloader:Win32/Snojan.BB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Snojan.BB!MTB virus can do?

  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Snojan.BB!MTB?


File Info:

name: AE761AAAF7AAEE3ABCAF.mlw
path: /opt/CAPEv2/storage/binaries/f95dc8e7caf20f711ec47d2e7bb484bf0818248ac248b9f5979ff1920018910b
crc32: 5DCECE6B
md5: ae761aaaf7aaee3abcafed7f24d36c61
sha1: caa00f90a31acd8aa1ae45eb5fc4305f8925ec4c
sha256: f95dc8e7caf20f711ec47d2e7bb484bf0818248ac248b9f5979ff1920018910b
sha512: 816ac1e75f5021d9ec7d6cba48cc061c75fbee55fe160b20f9a538a5fc34194c12e8539ed7dd51b899d710f90570af4d44bc16dc265b2d84b8dc124cbab70550
ssdeep: 3072:1s348A4M3ryN6MhGkgS3PL67n5OkhBOPC/L/FnncrU:1TeM7yNEkgi81ECrJn
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T119F34B20A954E0F3E8A301F101446B716E71DD39161BCA87E3D6EFB999B4701DB983BE
sha3_384: c46ce1de9a734485ec1ec1bb0d135b2c2bfec1c0953320cf9678368355bf07ef881314d5ef65d2a1be85a5f07723acd2
ep_bytes: 5589e583ec146a01ff15d0524200e8dd
timestamp: 2014-07-01 18:02:13

Version Info:

0: [No Data]

TrojanDownloader:Win32/Snojan.BB!MTB also known as:

tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Agent.CYMT
CAT-QuickHealTrojan.AgentbIH.S20216328
McAfeeDownloader-FCJE!AE761AAAF7AA
Cylanceunsafe
ZillyaTrojan.Agent.Win32.3405340
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0058cb101 )
K7AntiVirusTrojan ( 0058cb101 )
CyrenW32/S-f9d51e84!Eldorado
SymantecSMG.Heur!gen
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.AAEF
APEXMalicious
ClamAVWin.Malware.Snojan-6775202-0
KasperskyHEUR:Flooder.Win32.CoreWarrior.a
BitDefenderTrojan.Agent.CYMT
NANO-AntivirusTrojan.Win32.Snojan.jqzopm
AvastWin32:Banker-LAA [Trj]
TencentFlooder.Win32.CoreWarrior.ha
TACHYONTrojan/W32.CoreWarrior.159744
EmsisoftTrojan.Agent.CYMT (B)
F-SecureHeuristic.HEUR/AGEN.1330167
DrWebTool.Snojan.1
VIPRETrojan.Agent.CYMT
TrendMicroTROJ_GEN.R03BC0CEL23
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
FireEyeGeneric.mg.ae761aaaf7aaee3a
SophosTroj/Bdoor-BHD
IkarusTrojan.Win32.Agent
GDataWin32.Application.Snojan.A
JiangminDownloader.Snojan.adp
GoogleDetected
AviraHEUR/AGEN.1330167
Antiy-AVLRiskWare[Downloader]/Win32.Snojan
XcitiumTrojWare.Win32.Snojan.B@7h1cjp
ArcabitTrojan.Agent.CYMT
ZoneAlarmUDS:Flooder.Win32.CoreWarrior.a
MicrosoftTrojanDownloader:Win32/Snojan.BB!MTB
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win.Nemucod.C4762062
VBA32BScope.Trojan.Agentb
ALYacTrojan.Agent.CYMT
MAXmalware (ai score=83)
MalwarebytesMalware.AI.1684447551
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0CEL23
RisingTrojan.Agent!1.DEC9 (CLASSIC)
YandexTrojan.Agent!1wHGpufRGYc
MaxSecureTrojan.Malware.101660326.susgen
FortinetRiskware/Snojan
BitDefenderThetaGen:NN.ZexaF.36196.jCW@aCRfwAj
AVGWin32:Banker-LAA [Trj]
Cybereasonmalicious.af7aae
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Snojan.BB!MTB?

TrojanDownloader:Win32/Snojan.BB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment