Backdoor

Should I remove “Backdoor.Win32.Androm.pclz”?

Malware Removal

The Backdoor.Win32.Androm.pclz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.pclz virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Androm.pclz?


File Info:

crc32: 8D8836BD
md5: 79627ee7fb5d13bb585a73a06b0e058f
name: 79627EE7FB5D13BB585A73A06B0E058F.mlw
sha1: ff82214a18fd4377efd44b02cde60e9c3bba690e
sha256: 751781831097064c6bb8cd800943fde52c949cd254d3be2c1b319eabeb945468
sha512: fd153aabdf224b5020e7c62aa30e024df74a4448b0096140e7df2c15ff2882229dd820cfb09c57d0816ff27cd0883956cc70b5876f55fbff50639f319967bbca
ssdeep: 6144:rYVQjggxr4g67diBPsOv3X9KMeGiL4ASq0H7Tx:rCer4g67dUPs+3X9KMNyoHPx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Win32.Androm.pclz also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053305e1 )
Elasticmalicious (high confidence)
DrWebBackDoor.IRC.Bot.3517
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.ZZ5
ALYacTrojan.BRMon.Gen.3
CylanceUnsafe
ZillyaTrojan.GandCrypt.Win32.95
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Gandcrab.3e4e2a4c
K7GWTrojan ( 0056e9401 )
Cybereasonmalicious.7fb5d1
CyrenW32/S-60546053!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GDJU
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
KasperskyBackdoor.Win32.Androm.pclz
BitDefenderTrojan.BRMon.Gen.3
NANO-AntivirusTrojan.Win32.Bot.eydufd
ViRobotTrojan.Win32.Ransom.314880.G
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
MicroWorld-eScanTrojan.BRMon.Gen.3
TencentMalware.Win32.Gencirc.10b6a331
Ad-AwareTrojan.BRMon.Gen.3
SophosMal/Generic-R + Mal/GandCrab-B
ComodoTrojWare.Win32.Ransom.GandCrypt.C@7ivv6t
BitDefenderThetaGen:NN.ZexaF.34670.tuW@aSBd9kj
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_EMOTET.SMB1
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.79627ee7fb5d13bb
EmsisoftTrojan.BRMon.Gen.3 (B)
JiangminTrojan.GandCrypt.ag
AviraHEUR/AGEN.1126869
eGambitUnsafe.AI_Score_98%
KingsoftWin32.Hack.Androm.ai.(kcloud)
MicrosoftRansom:Win32/Gandcrab.SF!MTB
AegisLabTrojan.Win32.GandCrypt.tpk9
GDataTrojan.BRMon.Gen.3
AhnLab-V3Backdoor/Win32.Androm.C2436491
Acronissuspicious
McAfeePacked-FAG!79627EE7FB5D
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.GandCrypt
MalwarebytesTrojan.Downloader
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_EMOTET.SMB1
RisingMalware.Obscure!1.A3BB (CLOUD)
YandexTrojan.GandCrypt!8UKuFk44YcQ
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HCUD!tr
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml
Qihoo-360Win32/RootKit.Rootkit.7e5

How to remove Backdoor.Win32.Androm.pclz?

Backdoor.Win32.Androm.pclz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment