Backdoor

How to remove “Backdoor.Win32.Androm.txbt”?

Malware Removal

The Backdoor.Win32.Androm.txbt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.txbt virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Backdoor.Win32.Androm.txbt?


File Info:

crc32: 9D4EFAA8
md5: e72a5536533d9f2b313631e11c870e81
name: skyppe.exe
sha1: 791ae68a7d4a241e61456ff506ccb6b94b938d3e
sha256: 4bdae1ad10c5738002f25b3d9a2ac266e1c2ff8b04e836afee37c11ca8a0aad3
sha512: fab7c67c3823de94803a9c8c4c99a4e26837955987119f7548247962f824a2f263b9a703d53f0da6474fe42417c3deac5fa442dd2cd7cd10b145c08ebe8f3090
ssdeep: 24576:OAHnh+eWsN3skA4RV1Hom2KXSmdaioRuNgX0Xoqi9+7ShlWSbt1yTr5:5h+ZkldoPKi2aiKum0Yqi9ThlW6H0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Backdoor.Win32.Androm.txbt also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.33561894
FireEyeGeneric.mg.e72a5536533d9f2b
McAfeeArtemis!E72A5536533D
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderTrojan.GenericKD.33561894
K7GWTrojan ( 005633331 )
K7AntiVirusTrojan ( 005633331 )
TrendMicroTROJ_GEN.R002C0DCO20
F-ProtW32/Autoit.G.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0DCO20
AvastScript:SNH-gen [Trj]
GDataTrojan.GenericKD.33561894
KasperskyBackdoor.Win32.Androm.txbt
AlibabaBackdoor:Win32/Androm.3e7a0c4d
AegisLabHacktool.Win32.Gamehack.3!e
RisingTrojan.Obfus/Autoit!1.C408 (CLASSIC)
Ad-AwareTrojan.GenericKD.33561894
EmsisoftTrojan.GenericKD.33561894 (B)
ComodoMalware@#11phygco6dcap
F-SecureTrojan.TR/Autoit.hswnu
DrWebTrojan.KillProc2.9409
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
APEXMalicious
CyrenW32/Autoit.G.gen!Eldorado
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Autoit.hswnu
Antiy-AVLGrayWare/Autoit.BinToStr.a
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D2001D26
ZoneAlarmBackdoor.Win32.Androm.txbt
MicrosoftTrojan:Win32/Predator.BD!MTB
TACHYONBackdoor/W32.Androm.1217536
AhnLab-V3Trojan/AU3.Wacatac.S1079
VBA32Trojan.Wacatac
ALYacTrojan.GenericKD.33561894
MAXmalware (ai score=86)
MalwarebytesSpyware.PasswordStealer
PandaTrj/CI.A
ESET-NOD32MSIL/Spy.Agent.AES
TencentWin32.Backdoor.Androm.Airq
IkarusTrojan-Spy.HawkEye
eGambitUnsafe.AI_Score_99%
FortinetAutoIt/Injector.FCK!tr
WebrootW32.Trojan.Gen
AVGScript:SNH-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.b4f

How to remove Backdoor.Win32.Androm.txbt?

Backdoor.Win32.Androm.txbt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment