Backdoor

Backdoor.Win32.Androm.txrt (file analysis)

Malware Removal

The Backdoor.Win32.Androm.txrt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.txrt virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Androm.txrt?


File Info:

crc32: FC1063AE
md5: 35b7fb6b007c005569328245d77d52ad
name: order-1.exe
sha1: 6ed67c40dd0a27b77da982fb4a86d48e3d2572b5
sha256: 7a78c542ae12caf72a39730156249d086e3894908c83dc13a35681597e976ac7
sha512: f2c6d27bac5db8f9a9c93603f3f70bed761099ccb9ac35d5204ee181b7e240cc55ceed482d976848572c49d7a1d52b6cd6fd8c40d86728b13f907a52e7fc05f2
ssdeep: 24576:DCdxte/80jYLT3U1jfsWaf/ztEmbyL+Ai0fCrD8Qba5/Izsmd7oDQ:Kw80cTsjkWafrWPbi0sDRbuFmtV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Backdoor.Win32.Androm.txrt also known as:

DrWebTrojan.AutoIt.803
MicroWorld-eScanTrojan.GenericKD.42913430
McAfeeArtemis!35B7FB6B007C
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!e
SangforMalware
K7AntiVirusTrojan ( 005639c11 )
BitDefenderTrojan.GenericKD.42913430
K7GWTrojan ( 005639c11 )
CrowdStrikewin/malicious_confidence_70% (W)
TrendMicroTROJ_GEN.R002C0PD320
F-ProtW32/AutoIt.LN.gen!Eldorado
APEXMalicious
AvastScript:SNH-gen [Trj]
GDataWin32.Packed.Kryptik.H8BV7C
KasperskyBackdoor.Win32.Androm.txrt
AlibabaBackdoor:Win32/Androm.df4038ad
ViRobotTrojan.Win32.Z.Autoit.1524224.C
RisingTrojan.Obfus/Autoit!1.C075 (CLASSIC)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.42913430 (B)
F-SecureTrojan.TR/Autoit.smnta
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.35b7fb6b007c0055
SophosMal/Generic-S
IkarusTrojan.Autoit
CyrenW32/AutoIt.LN.gen!Eldorado
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Autoit.smnta
WebrootW32.Trojan.Gen
Antiy-AVLGrayWare/Autoit.BinToStr.a
ArcabitTrojan.Generic.D28ECE96
ZoneAlarmBackdoor.Win32.Androm.txrt
MicrosoftTrojan:Win32/Wacatac.C!ml
TACHYONBackdoor/W32.Androm.1524224
ALYacTrojan.GenericKD.42913430
MAXmalware (ai score=99)
VBA32Backdoor.Androm
MalwarebytesTrojan.Injector.AutoIt
ZonerTrojan.Win32.88941
ESET-NOD32a variant of Win32/Injector.Autoit.FES
TrendMicro-HouseCallTROJ_GEN.R002C0PD320
TencentWin32.Backdoor.Androm.Lkxr
eGambitUnsafe.AI_Score_56%
FortinetAutoIt/Injector.FES!tr
Ad-AwareTrojan.GenericKD.42913430
AVGScript:SNH-gen [Trj]
Cybereasonmalicious.0dd0a2
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.8c2

How to remove Backdoor.Win32.Androm.txrt?

Backdoor.Win32.Androm.txrt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment