Backdoor

What is “Backdoor.Win32.Androm.tvzh”?

Malware Removal

The Backdoor.Win32.Androm.tvzh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.tvzh virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Androm.tvzh?


File Info:

crc32: BEC3A031
md5: 50b1d1dfece17fe955bf9da7942c5a73
name: vbc.exe
sha1: 850b3f601b12b29834662eaeccbf3a0b64a1865d
sha256: f5c9d7e1a4975f9854ffcd690b4ca54dfd4007f48e290300c137c996cdf0f2c7
sha512: ddf81af3cd83e0f9f496c56943ee34c9e40aceefc962233f6c5abe83376b24db8d0329a685f680d6c433594717e67dfa1c7a4fd611438ea053bba5a4988a2edb
ssdeep: 768:5tIU7caIyqWimCZ2iow8edh6hqIILo3XE8DvR0Yi/GsIqY:5aU7cVVWjijmhzILoH5R0z/SZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Nation
InternalName: Albed9
FileVersion: 1.00
CompanyName: pourp
LegalTrademarks: egotr
Comments: usvige
ProductName: Leuco1
ProductVersion: 1.00
FileDescription: topplegr
OriginalFilename: Albed9.exe

Backdoor.Win32.Androm.tvzh also known as:

MicroWorld-eScanTrojan.GenericKD.42830523
McAfeeFareit-FRP!50B1D1DFECE1
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42830523
K7GWRiskware ( 0040eff71 )
TrendMicroTROJ_FRS.VSNTC920
BitDefenderThetaGen:NN.ZevbaCO.34098.em0@aer7gAdi
F-ProtW32/Injector.ZY.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_FRS.VSNTC920
AvastWin32:Trojan-gen
GDataWin32.Trojan-Downloader.Dagurleo.R59YBY
KasperskyBackdoor.Win32.Androm.tvzh
RisingBackdoor.Androm!8.113 (CLOUD)
Ad-AwareTrojan.GenericKD.42830523
SophosMal/Generic-S
DrWebTrojan.Siggen9.18631
McAfee-GW-EditionFareit-FRP!50B1D1DFECE1
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.42830523 (B)
APEXMalicious
CyrenW32/Injector.ZY.gen!Eldorado
eGambitUnsafe.AI_Score_99%
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D28D8ABB
ZoneAlarmBackdoor.Win32.Androm.tvzh
MicrosoftTrojan:Win32/VBInject.BS!MTB
AhnLab-V3Trojan/Win32.VBKrypt.C4007141
MAXmalware (ai score=84)
MalwarebytesTrojan.MalPack.VB
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EKYI
TencentWin32.Backdoor.Androm.Suxl
IkarusTrojan.VB.Crypt
FortinetW32/GenKryptik.EFWG!tr
WebrootW32.Trojan.Gen
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Backdoor.d1f

How to remove Backdoor.Win32.Androm.tvzh?

Backdoor.Win32.Androm.tvzh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment