Backdoor

How to remove “Backdoor.Win32.Androm.toyf”?

Malware Removal

The Backdoor.Win32.Androm.toyf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.toyf virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Androm.toyf?


File Info:

crc32: 2737F8C8
md5: 69efa8dd131a50d1b01c2513ee22c9b1
name: 1920.exe
sha1: 169a482734d448e500a5010b7f27e9ab9edad2e7
sha256: daabe515b411742064ba5a5a3645f49d7731c090276b1cddb62b2b60d2256254
sha512: e2df1443f102c32c8a008aa968039034cb0110bbab69554d7d3d15145ec30cab2eaf45a54c0214deb8404d89d6c62a4bb9d764dfddcaebd4829355ebf98b8306
ssdeep: 24576:lL3AkRQxX05rMUkfybyUHN4bQlVdYusvXJ:lLSJ4MdyxNrlwrJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
InternalName: TRUCIOLato
FileVersion: 7.00
CompanyName: asuS
ProductName: GIROEFfect5
ProductVersion: 7.00
OriginalFilename: TRUCIOLato.exe

Backdoor.Win32.Androm.toyf also known as:

MicroWorld-eScanGen:Variant.Symmi.78222
ALYacGen:Variant.Symmi.78222
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0055c5511 )
BitDefenderGen:Variant.Symmi.78222
K7GWTrojan ( 0055c5511 )
Cybereasonmalicious.d131a5
Invinceaheuristic
BitDefenderThetaGen:NN.ZevbaF.32515.on0@aOmE5Gfb
F-ProtW32/Injector.VK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EJEX
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Symmi.78222
KasperskyBackdoor.Win32.Androm.toyf
AlibabaBackdoor:Win32/Androm.f68c0be8
NANO-AntivirusTrojan.Win32.GenKryptik.gjmirs
AegisLabTrojan.Win32.Symmi.4!c
Ad-AwareGen:Variant.Symmi.78222
SophosMal/FareitVB-X
F-SecureTrojan.TR/Kryptik.bdara
DrWebTrojan.Siggen8.58040
McAfee-GW-EditionBehavesLike.Win32.VBObfus.th
FireEyeGeneric.mg.69efa8dd131a50d1
EmsisoftGen:Variant.Symmi.78222 (B)
IkarusTrojan.VB.Crypt
CyrenW32/Injector.VK.gen!Eldorado
JiangminBackdoor.Androm.arra
WebrootW32.Trojan.Ursu
AviraTR/Kryptik.bdara
MAXmalware (ai score=87)
Endgamemalicious (high confidence)
ArcabitTrojan.Symmi.D1318E
AhnLab-V3Win-Trojan/VBKrand.Gen
ZoneAlarmBackdoor.Win32.Androm.toyf
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
McAfeeFareit-FPZ!69EFA8DD131A
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H09KR19
SentinelOneDFI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.DYQQ!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Backdoor.326

How to remove Backdoor.Win32.Androm.toyf?

Backdoor.Win32.Androm.toyf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment