Backdoor

What is “Backdoor.Win32.Androm.txdj”?

Malware Removal

The Backdoor.Win32.Androm.txdj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.txdj virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Androm.txdj?


File Info:

crc32: E2A656C9
md5: be7cee511ae69180448a4fb349538bda
name: regasm.exe
sha1: 766a15195a725dc3b9e9ce2e2bf40ebdc86524a0
sha256: ee037e3764b0b8bbfc71172d6dced602bd76763806ac6599e408a66995a23b5d
sha512: 50daf27b41f1b6130a6701cad5f8481d9dbf0dbd9941576b3c46338df364d6b99e33c96dbbd658f66f9644f62a38b7e81eac4df2904b8c404d291f842913b65b
ssdeep: 24576:JAHnh+eWsN3skA4RV1Hom2KXSmdaCtsu9Nn+BG05NYBQrl35:Qh+ZkldoPKi2aCKu9NnGd5CBQrD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Backdoor.Win32.Androm.txdj also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.Autoit.RQS
FireEyeGeneric.mg.be7cee511ae69180
McAfeeArtemis!BE7CEE511AE6
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005633331 )
BitDefenderTrojan.Autoit.RQS
K7GWTrojan ( 005633331 )
TrendMicroTROJ_GEN.R011C0DCO20
F-ProtW32/Autoit.G.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastScript:SNH-gen [Trj]
GDataTrojan.Autoit.RQS
KasperskyBackdoor.Win32.Androm.txdj
AlibabaBackdoor:Win32/Androm.8d4beb06
ViRobotTrojan.Win32.Z.Autoit.1259520.B
AegisLabHacktool.Win32.Gamehack.3!e
TencentWin32.Backdoor.Androm.Pika
Endgamemalicious (high confidence)
SophosMal/Generic-S
ComodoMalware@#3d4k2yk93qpf8
F-SecureTrojan.TR/Autoit.nyofg
DrWebTrojan.AutoIt.788
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
EmsisoftTrojan.Autoit.RQS (B)
IkarusTrojan-Spy.HawkEye
CyrenW32/Autoit.G.gen!Eldorado
eGambitUnsafe.AI_Score_97%
AviraTR/Autoit.nyofg
MAXmalware (ai score=83)
Antiy-AVLGrayWare/Autoit.BinToStr.a
ArcabitTrojan.Autoit.RQS
ZoneAlarmBackdoor.Win32.Androm.txdj
MicrosoftTrojan:Win32/Predator.BD!MTB
AhnLab-V3Trojan/AU3.Wacatac.S1079
MalwarebytesSpyware.LokiBot
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.Autoit.FEG
TrendMicro-HouseCallTROJ_GEN.R011C0DCO20
RisingTrojan.Obfus/Autoit!1.C12C (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
FortinetAutoIt/Injector.FCK!tr
AVGScript:SNH-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Win32/Backdoor.a20

How to remove Backdoor.Win32.Androm.txdj?

Backdoor.Win32.Androm.txdj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment