Backdoor

What is “Backdoor.Win32.Androm.twjs”?

Malware Removal

The Backdoor.Win32.Androm.twjs is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.twjs virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Creates a hidden or system file
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
cpf-th.com

How to determine Backdoor.Win32.Androm.twjs?


File Info:

crc32: 0A94C585
md5: 09295775fc8f9862d367842e0abdec99
name: taskhost.exe
sha1: c82f4b4f884c1505c6e7b4b3942725dfcee93ef0
sha256: 60bdc0e3d521502cebc178e4373919f76981d62a00901330b6a60f06734579d3
sha512: 72e298838e817a34480db818cc6d2715b803fe8da02a44818b0fcd92ac0806d07474afbc9b46371ee54c48d7b8f9a42e72317d046e82b9a349fb69d0e5dcf77d
ssdeep: 24576:rtb20pkaCqT5TBWgNQ7az4WehNyfxoqXekALIA0VWI6A:oVg5tQ7az4WIyHXeAA0N5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Backdoor.Win32.Androm.twjs also known as:

DrWebTrojan.Siggen9.20465
MicroWorld-eScanTrojan.GenericKD.33539807
FireEyeGeneric.mg.09295775fc8f9862
Qihoo-360Win32/Backdoor.1f6
McAfeeArtemis!09295775FC8F
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005625401 )
BitDefenderTrojan.GenericKD.33539807
K7GWTrojan ( 005625401 )
CrowdStrikewin/malicious_confidence_60% (W)
TrendMicroTrojanSpy.AutoIt.NEGASTEAL.SM.hp
SymantecPacked.Generic.548
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.33539807
KasperskyBackdoor.Win32.Androm.twjs
AlibabaBackdoor:Win32/Androm.d4cbbd95
AegisLabTrojan.Win32.AutoIt.4!c
AvastScript:SNH-gen [Trj]
RisingTrojan.Obfus/Autoit!1.C3D3 (CLASSIC)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.33539807 (B)
ComodoMalware@#1l9rbwmpf8ab1
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan-Spy.HawkEye
CyrenW32/AutoIt.OM.gen!Eldorado
MAXmalware (ai score=91)
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Generic.D1FFC6DF
ZoneAlarmBackdoor.Win32.Androm.twjs
AhnLab-V3Win-Trojan/AutoInj.Exp
ALYacTrojan.Autoit.Injector
MalwarebytesTrojan.MalPack.AutoIt
ESET-NOD32a variant of Win32/Injector.Autoit.FDS
TrendMicro-HouseCallTrojanSpy.AutoIt.NEGASTEAL.SM.hp
TencentWin32.Backdoor.Androm.Eer
eGambitUnsafe.AI_Score_80%
FortinetAutoIt/Injector.FDH!tr
Ad-AwareTrojan.GenericKD.33539807
AVGScript:SNH-gen [Trj]
Cybereasonmalicious.f884c1
PandaTrj/CI.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Backdoor.Win32.Androm.twjs?

Backdoor.Win32.Androm.twjs removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment