Categories: Backdoor

Backdoor.Win32.Androm.tkqj removal guide

The Backdoor.Win32.Androm.tkqj file is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Backdoor.Win32.Androm.tkqj virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Creates a hidden or system file
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system

How to determine Backdoor.Win32.Androm.tkqj?


General:

Operating System: Windows 7 / 8 / 8.1 / 10 Virus Name: Malware@#t55d2yozc5nq

File Info:

Name: lky.exe

Size: 226390

Type: PE32 executable (GUI) Intel 80386, for MS Windows

MD5: 51a3af0843364aeda930476ebaf3102f

SHA1: 439dcaf280b2384060ed9237dce68fabdce39031

SH256: 4acc26b5f79c556cbb1a396ea8666739e8992399739e6179e216cf52b81a5821

Version Info:

[No Data]

Backdoor.Win32.Androm.tkqj also known as:

ALYac Spyware.LokiBot
APEX Malicious
AVG Win32:Trojan-gen
Acronis suspicious
Ad-Aware Trojan.GenericKD.32648454
AegisLab Trojan.Win32.Androm.m!c
AhnLab-V3 Malware/Win32.Generic.C3534682
Alibaba Backdoor:Win32/Androm.eb287adc
Antiy-AVL Trojan[Backdoor]/Win32.Androm
Arcabit Trojan.Generic.D1F22D06
Avira HEUR/AGEN.1039972
BitDefender Trojan.GenericKD.32648454
BitDefenderTheta Gen:NN.ZexaF.32245.ny3@aKbRpSli
CAT-QuickHeal Backdoor.Androm
Comodo Malware@#t55d2yozc5nq
CrowdStrike win/malicious_confidence_80% (W)
Cybereason malicious.280b23
Cylance Unsafe
Cyren W32/Trojan.AEYL-6519
DrWeb Trojan.PWS.Stealer.25838
ESET-NOD32 a variant of Win32/GenKryptik.DWIQ
Emsisoft Trojan.GenericKD.32648454 (B)
Endgame malicious (high confidence)
F-Secure Heuristic.HEUR/AGEN.1039972
FireEye Generic.mg.51a3af0843364aed
Fortinet W32/Kryptik.GWYH!tr
GData Trojan.GenericKD.32648454
Ikarus Trojan.Win32.Krypt
Invincea heuristic
Jiangmin Trojan.PSW.Azorult.epd
K7AntiVirus Trojan ( 0055a6c31 )
K7GW Trojan ( 0055a6c31 )
Kaspersky Backdoor.Win32.Androm.tkqj
MAX malware (ai score=83)
Malwarebytes Spyware.PasswordStealer.XMP.Generic
McAfee RDN/Generic BackDoor
McAfee-GW-Edition BehavesLike.Win32.Expiro.dc
MicroWorld-eScan Trojan.GenericKD.32648454
Microsoft Trojan:Win32/Azorult.PC!MTB
NANO-Antivirus Trojan.Win32.Azorult.getfyz
Paloalto generic.ml
Panda Trj/CI.A
Qihoo-360 Win32/Backdoor.0f6
Rising Trojan.Kryptik!1.BE72 (CLASSIC)
SentinelOne DFI – Malicious PE
Sophos Mal/Generic-S
Symantec Trojan.Gen.MBT
Trapmine suspicious.low.ml.score
TrendMicro-HouseCall TROJ_GEN.R015C0WJR19
VBA32 Backdoor.Androm
VIPRE Trojan.Win32.Generic!BT
ViRobot Trojan.Win32.Z.Agent.226390
Webroot W32.Trojan.Gen
Yandex Backdoor.Androm!YbuuBkppCIY
ZoneAlarm Backdoor.Win32.Androm.tkqj

How to remove Backdoor.Win32.Androm.tkqj?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

About “Malware.AI.2023067230” infection

The Malware.AI.2023067230 is considered dangerous by lots of security experts. When this infection is active,…

4 mins ago

How to remove “Malware.AI.3523790349”?

The Malware.AI.3523790349 is considered dangerous by lots of security experts. When this infection is active,…

15 mins ago

Win32/Adware.Kraddare.MI removal

The Win32/Adware.Kraddare.MI is considered dangerous by lots of security experts. When this infection is active,…

15 mins ago

Worm.Win32.Vobfus.exgr malicious file

The Worm.Win32.Vobfus.exgr is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Should I remove “MSIL/TrojanDownloader.Agent_AGen.BHA”?

The MSIL/TrojanDownloader.Agent_AGen.BHA is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

About “CNav (PUA)” infection

The CNav (PUA) is considered dangerous by lots of security experts. When this infection is…

1 hour ago