Backdoor

About “Backdoor.Win32.Androm.tphy” infection

Malware Removal

The Backdoor.Win32.Androm.tphy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.tphy virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Network activity detected but not expressed in API logs

How to determine Backdoor.Win32.Androm.tphy?


File Info:

crc32: A1DCFA0F
md5: d327ad4c1bd8fd55bd818b4d36103b2f
name: sunnycrr.exe
sha1: b59813e42ad4966b348d7e8b9383f0482f02ba6c
sha256: 20348e076edc91a21bb43f1de7d6e3d32210eecf82779e498500ab433d91182e
sha512: c01255df5af463d61e937b5efffb9c2cd0be1f8e8eb87d39645a9c86be6606df17d12ea28081effd8f8398586ddfd9a26b2f162ad9352256c8a11f39ddf2b89c
ssdeep: 6144:FcksE0Bh/MUlE7t+v5EUS9+xbMHydmLpXXc:jm/AuvS9+xYSdmVXc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) prestezza 2019
InternalName: Steedman.exe
FileVersion: 0.0.4.7
CompanyName: harico
ProductName: fleamy
ProductVersion: 7.5.0.0
FileDescription: antipyic
OriginalFilename: proboscidian.exe
Translation: 0x0409 0x04b0

Backdoor.Win32.Androm.tphy also known as:

MicroWorld-eScanTrojan.GenericKD.32781152
FireEyeGeneric.mg.d327ad4c1bd8fd55
McAfeeRDN/Generic.hra
MalwarebytesTrojan.MalPack
SangforMalware
K7AntiVirusTrojan ( 0055cbda1 )
BitDefenderTrojan.GenericKD.32781152
K7GWTrojan ( 0055cbda1 )
Cybereasonmalicious.42ad49
BitDefenderThetaGen:NN.ZexaF.32519.Ky3@aeaQodpi
F-ProtW32/Kryptik.AUA.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.GZCH
TrendMicro-HouseCallTROJ_FRS.VSNW04L19
AvastWin32:Malware-gen
GDataTrojan.GenericKD.32781152
KasperskyBackdoor.Win32.Androm.tphy
AlibabaTrojan:Win32/GenKryptik.8e1eb0d9
NANO-AntivirusTrojan.Win32.Kryptik.gkmtht
AegisLabTrojan.Win32.Malicious.4!c
RisingDropper.Generic!8.35E (TFE:5:NGbMXt8E3KP)
Endgamemalicious (high confidence)
EmsisoftTrojan-Spy.Agent (A)
ComodoMalware@#zs1fqsx71ab3
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen8.60636
ZillyaBackdoor.Androm.Win32.69699
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.hm
Trapminemalicious.high.ml.score
SophosTroj/Fareit-JGX
APEXMalicious
CyrenW32/Kryptik.AUA.gen!Eldorado
JiangminTrojan.Gorgon.ku
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan[PSW]/Win32.Azorult
MicrosoftTrojan:Win32/Azorult.PF!MTB
ArcabitTrojan.Generic.D1F43360
AhnLab-V3Malware/Win32.Generic.C3611191
ZoneAlarmBackdoor.Win32.Androm.tphy
ALYacSpyware.LokiBot
Ad-AwareTrojan.GenericKD.32781152
CylanceUnsafe
PandaTrj/Agent.JB
IkarusTrojan.Win32.Krypt
FortinetW32/GenKryptik.DZEJ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Backdoor.17f

How to remove Backdoor.Win32.Androm.tphy?

Backdoor.Win32.Androm.tphy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment