Backdoor

How to remove “Backdoor.Win32.Androm.twqm”?

Malware Removal

The Backdoor.Win32.Androm.twqm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.twqm virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to modify proxy settings

How to determine Backdoor.Win32.Androm.twqm?


File Info:

crc32: 87653393
md5: 81a5eea229359c1472ed15a455cc64d5
name: svchost.exe
sha1: a57ea751763841401d7b3b9793d0e6ee74e23602
sha256: 0afe4596b0abc61aff3c66dc68e57c6dd81b8e7ceeaef221c4034f289bf947e6
sha512: 0918740e5ce781d6b9a9d4257bbb78824dd705c1e9c92e962af220cbfca18d2cae5abff97b6346ef54c4b856b9546fba0ccaa0e82125f81eae81347695dc6238
ssdeep: 24576:wkS2NJMhlQPr6b5K7QDfA7YJUWwlSfgcMeu5BMJ9AoGn:wkS2XfshUfpeIMJrA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Comfort Software Group (C) 2007-2015
InternalName: RecycledDecelerated
CompanyName: Comfort Software Group
LegalTrademarks: Comfort Software Group (C) 2007-2015
Comments: Daemon Correlating House Retrspective
ProductName: RecycledDecelerated
ProductVersion: 6.6.1.5
FileDescription: Daemon Correlating House Retrspective
Translation: 0x0409 0x04b0

Backdoor.Win32.Androm.twqm also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.33551608
FireEyeGeneric.mg.81a5eea229359c14
Qihoo-360Win32/Backdoor.86f
McAfeeArtemis!81A5EEA22935
AegisLabTrojan.Win32.Malicious.4!c
K7AntiVirusTrojan ( 00562e231 )
BitDefenderTrojan.GenericKD.33551608
K7GWTrojan ( 00562e231 )
CrowdStrikewin/malicious_confidence_70% (W)
Invinceaheuristic
SymantecTrojan.Gen.MBT
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.33551608
KasperskyBackdoor.Win32.Androm.twqm
AlibabaBackdoor:Win32/Androm.63a1d421
ViRobotTrojan.Win32.Z.Agent.1239552
TencentWin32.Backdoor.Androm.Dztl
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.Agent.gfghz
DrWebTrojan.PWS.Stealer.23680
TrendMicroMal_HPGen-37b
McAfee-GW-EditionBehavesLike.Win32.Generic.th
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.33551608 (B)
IkarusTrojan-Spy.Remcos
CyrenW32/Trojan.MWLM-0005
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.gfghz
Antiy-AVLTrojan[Backdoor]/Win32.Androm
ArcabitTrojan.Generic.D1FFF4F8
ZoneAlarmBackdoor.Win32.Androm.twqm
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Trojan/Win32.Agent.C4020384
VBA32BScope.Trojan.Casur
ALYacBackdoor.Remcos.A
Ad-AwareTrojan.GenericKD.33551608
MalwarebytesTrojan.MalPack.RVRS
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.HCBC
TrendMicro-HouseCallMal_HPGen-37b
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetPossibleThreat.MU
BitDefenderThetaGen:NN.ZexaF.34100.lr0@aeCwdSpi
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Backdoor.Win32.Androm.twqm?

Backdoor.Win32.Androm.twqm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment