Backdoor

Backdoor.Win32.Androm.cvr malicious file

Malware Removal

The Backdoor.Win32.Androm.cvr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.cvr virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Removes Security and Maintenance icon from Start menu, Taskbar and notifications
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Attempts to stop active services
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • CAPE detected the Andromeda malware family
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Attempts to disable UAC
  • Attempts to modify user notification settings

How to determine Backdoor.Win32.Androm.cvr?


File Info:

name: BD0FC0259AB9D26E6BB3.mlw
path: /opt/CAPEv2/storage/binaries/67f39d8258920de8aa86992a5bf40f7e9e03167c4716224b91eee73b37bf0dff
crc32: 84D5303B
md5: bd0fc0259ab9d26e6bb35bded882b785
sha1: f4f4cb83893e97ca4e4b6f8335ecea090d171573
sha256: 67f39d8258920de8aa86992a5bf40f7e9e03167c4716224b91eee73b37bf0dff
sha512: f1df64c9aea3239a1b5263b2507932b47d081b43804941de6902284f54a8b475c2fd01126b5420478f1ac07c9dc0c2d9829ac1cddf00173a95e744367a43ce72
ssdeep: 3072:U6mtg2vup51r/D7ORSBOqZ2+UctbhwXF:U6mtvu5r/fORSBCw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CCC3C041B5D08AFFC8AA40714CD65E9A9BB9BC314F211C87A7F4964B4D657E2243B03F
sha3_384: 5ae4c733f4a9be793ebc0a6b2f38e67d37bd3d8c84adba54ac94c682bce799c525f379da380f8c2b9b12ae6d50746473
ep_bytes: 558bec6aff68d851410068ccc2400064
timestamp: 2014-03-19 09:37:17

Version Info:

CompanyName: Herz
FileDescription: Herz
FileVersion: 1.0
InternalName: Herz
LegalTrademarks1:
Translation: 0x0409 0x04e4

Backdoor.Win32.Androm.cvr also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lt1a
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.bd0fc0259ab9d26e
CAT-QuickHealWorm.Gamarue.I5
ALYacTrojan.GenericKD.1610826
CylanceUnsafe
ZillyaBackdoor.Androm.Win32.6846
SangforTrojan.Win32.Dropper.atgen
K7AntiVirusTrojan-Downloader ( 00492f161 )
AlibabaWorm:Win32/Gamarue.b038a795
K7GWTrojan-Downloader ( 00492f161 )
CrowdStrikewin/malicious_confidence_90% (W)
VirITTrojan.Win32.Dropper.DB
CyrenW32/Trojan.TLVR-4726
SymantecPacked.Generic.453
ESET-NOD32Win32/TrojanDownloader.Wauchos.Z
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Androm.cvr
BitDefenderTrojan.GenericKD.1610826
NANO-AntivirusTrojan.Win32.Androm.dayipl
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
MicroWorld-eScanTrojan.GenericKD.1610826
AvastWin32:Dropper-gen [Drp]
TencentWin32.Backdoor.Androm.Pfjj
Ad-AwareTrojan.GenericKD.1610826
EmsisoftTrojan.GenericKD.1610826 (B)
ComodoTrojWare.Win32.Kryptik.BXN@58sdhj
DrWebBackDoor.Andromeda.267
VIPRETrojan.Win32.Zbot.htk (v)
TrendMicroTROJ_WEELSOF.VLR
McAfee-GW-EditionGeneric.sp
SophosML/PE-A + Troj/Zbot-HUJ
IkarusTrojan.Win32.Weelsof
GDataWin32.Trojan.Agent.3EM346
JiangminBackdoor/Androm.clb
WebrootDownloader.Wauchos.Z
AviraTR/Crypt.Epack.51080
Antiy-AVLTrojan/Win32.SGeneric
KingsoftWin32.Troj.Agent.zz.(kcloud)
ArcabitTrojan.Generic.D18944A
ViRobotTrojan.Win32.Zbot.122880.F
ZoneAlarmBackdoor.Win32.Androm.cvr
MicrosoftWorm:Win32/Gamarue.I
AhnLab-V3Win-Trojan/Zbot.122880.CL
McAfeePWSZbot-FTY
MAXmalware (ai score=100)
VBA32Backdoor.Androm
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_WEELSOF.VLR
RisingBackdoor.Win32.Androm.ge (CLOUD)
YandexTrojan.DL.Wauchos!NT/vMMTEVWU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.OAQ!tr
BitDefenderThetaAI:Packer.F1463E2221
AVGWin32:Dropper-gen [Drp]
PandaTrj/WLT.A

How to remove Backdoor.Win32.Androm.cvr?

Backdoor.Win32.Androm.cvr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment