Backdoor

Backdoor.Win32.Androm.tvap (file analysis)

Malware Removal

The Backdoor.Win32.Androm.tvap is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.tvap virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Creates a hidden or system file
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system

Related domains:

naourl.com

How to determine Backdoor.Win32.Androm.tvap?


File Info:

crc32: 25325A46
md5: 66f33597cbf097345c51891ab951b641
name: taskhost.exe
sha1: 70ad543faecb496ca4c2318e0c8f81a8cbb8fb62
sha256: 0da91175e7d72a7ff2bcb3fd93f2ba7bbe4045f9c4dee5c9685c7fdf6da622a6
sha512: d9d4f057dc3c09e1ba42c08ee204e86b569233378d2367a6d6cc67c67b5e2ef87c2b4b9387036bd76f6c06d085079b1f095399465d9e9278d8cd1569b0e02839
ssdeep: 24576:Pu6J33O0c+JY5UZ+XC0kGso6FaODoki222F0Eci4GIxmWY:5u0c++OCvkGs9FaOHN22F9QY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Backdoor.Win32.Androm.tvap also known as:

MicroWorld-eScanTrojan.GenericKD.33379966
CAT-QuickHealWorm.vinf
Qihoo-360Generic/Trojan.28d
McAfeeArtemis!66F33597CBF0
CylanceUnsafe
VIPREWin32.Malware!Drop
AegisLabTrojan.Win32.Autoit.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderTrojan.GenericKD.33379966
K7GWTrojan ( 005612d91 )
K7AntiVirusTrojan ( 005612d91 )
ArcabitTrojan.Generic.D1FD567E
Invinceaheuristic
SymantecPacked.Generic.548
ESET-NOD32a variant of Win32/Injector.Autoit.FCS
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Androm.tvap
AlibabaTrojanDownloader:Win32/Dawnla.ecf4ec60
NANO-AntivirusTrojan.Win32.Androm.hcxkyp
ViRobotTrojan.Win32.Z.Autoit.1217024
Ad-AwareTrojan.GenericKD.33379966
EmsisoftTrojan.GenericKD.33379966 (B)
ComodoMalware@#1w4q5cn7joxa2
F-SecureTrojan.TR/Autoit.xgnqw
DrWebTrojan.Siggen9.15321
TrendMicroTrojan.Win32.WACATAC.THBBFBO
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
FortinetAutoIt/Injector.FCK!tr
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.66f33597cbf09734
SophosMal/Generic-S
IkarusTrojan.Autoit
CyrenW32/Trojan.CHPN-0368
WebrootW32.Trojan.Autoit
AviraTR/Autoit.xgnqw
MAXmalware (ai score=83)
Antiy-AVLGrayWare/Autoit.Execute.a
Endgamemalicious (high confidence)
MicrosoftTrojanDownloader:Win32/Dawnla.A!MSR
ZoneAlarmBackdoor.Win32.Androm.tvap
AhnLab-V3Trojan/AU3.Wacatac.S1079
ALYacTrojan.Agent.Wacatac
MalwarebytesTrojan.MalPack.AutoIt
PandaTrj/CI.A
TrendMicro-HouseCallTrojan.Win32.WACATAC.THBBFBO
TencentWin32.Backdoor.Androm.Wrqp
GDataTrojan.GenericKD.33379966
AVGScript:SNH-gen [Trj]
Cybereasonmalicious.faecb4
AvastScript:SNH-gen [Trj]
MaxSecureTrojan.Malware.300983.susgen

How to remove Backdoor.Win32.Androm.tvap?

Backdoor.Win32.Androm.tvap removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment