Backdoor

About “Backdoor.Win32.Androm.tsbz” infection

Malware Removal

The Backdoor.Win32.Androm.tsbz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.tsbz virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • A process created a hidden window
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Androm.tsbz?


File Info:

crc32: 1474FA7C
md5: ce0ec340283f235e5df2b2d521199e8f
name: rxcvgfhhfdg.exe
sha1: 9a0ade588fe030bc52deb1fe405e199595d19b15
sha256: 8429d4522f1532829d8af26ddbd18669fab2ba8db8beb985a17b56e94ad80dec
sha512: e86310402b7445952509b7d1b938f81a90132bf80d5ba8536572c57fd61fd263d1d8e1854ae409cc292991a22f5a5fef0967a74a8519acf5a9feb27a81234799
ssdeep: 3072:Ry/NT+Mpk1WGUN05GWvF/f5VOqYTf0ZJ5OvrSWpMPZGrHZw5EUjJiT9xEUxyMq:w/ksNSf1wYBGrHgEBfUMq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) nationaliser 2019
InternalName: aggeration.exe
FileVersion: 5.8.2.1
CompanyName: trilletto
ProductName: NRAO
ProductVersion: 4.7.6.0
FileDescription: unkindling
OriginalFilename: Anglicising.exe
Translation: 0x0409 0x04b0

Backdoor.Win32.Androm.tsbz also known as:

MicroWorld-eScanGen:Variant.Ulise.96875
McAfeeRDN/Generic.hra
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Androm.m!c
SangforMalware
K7AntiVirusTrojan ( 0055f5801 )
BitDefenderGen:Variant.Ulise.96875
K7GWTrojan ( 0055f5801 )
Cybereasonmalicious.88fe03
TrendMicroTrojan.Win32.WACATAC.USXVPAQ20
CyrenW32/Trojan.NQLD-2655
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.ECRE
APEXMalicious
AvastWin32:Trojan-gen
KasperskyBackdoor.Win32.Androm.tsbz
AlibabaTrojan:Win32/GenKryptik.1df2bbcb
ViRobotTrojan.Win32.S.Ransom.216159
TencentWin32.Backdoor.Androm.Syru
Ad-AwareGen:Variant.Ulise.96875
EmsisoftGen:Variant.Ulise.96875 (B)
F-SecureTrojan.TR/Kryptik.qaisp
DrWebTrojan.Encoder.29362
Invinceaheuristic
McAfee-GW-EditionRDN/Generic.hra
FortinetW32/Generic.AP.20ADFE6!tr
FireEyeGeneric.mg.ce0ec340283f235e
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
JiangminTrojan.PSW.MSIL.lse
WebrootW32.Trojan.Gen
AviraTR/Kryptik.qaisp
MAXmalware (ai score=89)
Endgamemalicious (high confidence)
ArcabitTrojan.Ulise.D17A6B
ZoneAlarmBackdoor.Win32.Androm.tsbz
MicrosoftTrojan:Win32/Occamy.C
VBA32BScope.Trojan.Meterpreter
ALYacGen:Variant.Ulise.96875
PandaTrj/CI.A
TrendMicro-HouseCallTrojan.Win32.WACATAC.USXVPAQ20
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_98%
GDataGen:Variant.Ulise.96875
BitDefenderThetaGen:NN.ZexaF.34084.nC3@a0FhN9mi
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/HEUR/QVM10.2.D56D.Malware.Gen

How to remove Backdoor.Win32.Androm.tsbz?

Backdoor.Win32.Androm.tsbz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment