Backdoor

About “Backdoor.Win32.Androm.guih” infection

Malware Removal

The Backdoor.Win32.Androm.guih is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.guih virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Backdoor.Win32.Androm.guih?


File Info:

name: 5B4CF35DA41EC4BA6473.mlw
path: /opt/CAPEv2/storage/binaries/55fee0eb4bca9966959db2d57436c9672c9c7e3f9a1776a00a328cacad94f0cd
crc32: 20F07C99
md5: 5b4cf35da41ec4ba6473c574df1cccc5
sha1: b835a32174d58e80ce53c0bf7de3083355e23c17
sha256: 55fee0eb4bca9966959db2d57436c9672c9c7e3f9a1776a00a328cacad94f0cd
sha512: 7ec125eae0ac6a14002c27a49b5fc1bf9ecdf99a031e16e74159a63952edf848cf434df01623367720a784cfdd34f4e00906c10ddd1950d6efa3717ad354d8b7
ssdeep: 24576:jwKszFTy9syV1G1pMbgsli+Z+PiYINYXLE6Eni:jwKuFus48PMw/3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T196459E13B6F690F1C619267018BE2735EAB5AB161B11CFC39364DE2E5D331A0DE3B129
sha3_384: ae30e7fc70a81fb0d2bd6ac5ec5223c482a0fff2d2403dc811bcb5a9688d4d8eb1f286f99eb905653dd047b3440e0eb3
ep_bytes: 558bec6aff6848e4500068ccee440064
timestamp: 2015-05-03 06:18:14

Version Info:

0: [No Data]

Backdoor.Win32.Androm.guih also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.61329847
ClamAVWin.Malware.Qqpass-9877000-0
FireEyeGeneric.mg.5b4cf35da41ec4ba
CAT-QuickHealTrojan.Onlinegames.16894
McAfeeGenericRXEM-ZT!5B4CF35DA41E
CylanceUnsafe
ZillyaTrojan.Injector.Win32.1570069
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.da41ec
CyrenW32/A-b0178058!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.DGXX
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Androm.guih
BitDefenderTrojan.GenericKD.61329847
NANO-AntivirusTrojan.Win32.Androm.drrfuw
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Kryptik.ya
Ad-AwareTrojan.GenericKD.61329847
EmsisoftTrojan.GenericKD.61329847 (B)
ComodoWorm.Win32.Dropper.RA@1qraug
DrWebTrojan.DownLoader16.31084
VIPRETrojan.GenericKD.61329847
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
Trapminesuspicious.low.ml.score
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Injector
GDataWin32.Trojan.PSE.1THOGOA
AviraTR/AD.Inject.ulxlm
Antiy-AVLTrojan/Generic.ASMalwS.A9D
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.ZT.R508929
ALYacTrojan.GenericKD.61329847
MAXmalware (ai score=83)
MalwarebytesTrojan.Dropper
RisingTrojan.Tiggre!8.ED98 (TFE:5:JW2ha4RCbZN)
YandexTrojan.Pasta.Gen.1
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.65CA!tr
BitDefenderThetaGen:NN.ZexaF.34606.lrY@ay9@Trib
AVGWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Backdoor.Win32.Androm.guih?

Backdoor.Win32.Androm.guih removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment