Backdoor

Should I remove “Backdoor.Win32.Androm.uirx”?

Malware Removal

The Backdoor.Win32.Androm.uirx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.uirx virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Tswana
  • The executable is compressed using UPX
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Androm.uirx?


File Info:

crc32: 274246E9
md5: b808673dcdb743f305fdfd4d6fd239d5
name: B808673DCDB743F305FDFD4D6FD239D5.mlw
sha1: dd57d842ebbfb390733f313b0b1e321b44c04d14
sha256: 73bd0ef4821814fb351197b6967d35274f9f33de491faca434aeeb63a51072bb
sha512: 67884616b51ab8be9a662b2890c9eb176748611d36512ba49b8b9f211da6db90646ff87d69b169615b83bc26f58c4ae13b428386137312e2711e0a6635759acf
ssdeep: 3072:5JZWWzn7nDjDuNxDZ7uykppfwuwUwrXaeu4t8:AWr7nDuNRZ7ujlrClu4
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafull
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x054e

Backdoor.Win32.Androm.uirx also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36017158
FireEyeGeneric.mg.b808673dcdb743f3
McAfeeGenericRXAA-AA!B808673DCDB7
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00575bfa1 )
BitDefenderTrojan.GenericKD.36017158
K7GWTrojan ( 00575bfa1 )
Cybereasonmalicious.2ebbfb
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Androm.uirx
AlibabaBackdoor:Win32/Glupteba.56ec02d9
ViRobotTrojan.Win32.Z.Malpack.217600
AegisLabTrojan.Win32.Malicious.4!c
RisingTrojan.Kryptik!8.8 (TFE:5:V4nJcY6klTD)
Ad-AwareTrojan.GenericKD.36017158
EmsisoftTrojan.GenericKD.36017158 (B)
ComodoMalware@#45l5x6feu4zf
F-SecureTrojan.TR/AD.Behavior.hzata
DrWebTrojan.DownLoader36.33288
TrendMicroTROJ_GEN.R067C0DA921
McAfee-GW-EditionBehavesLike.Win32.Trojan.dh
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
AviraTR/AD.Behavior.hzata
MAXmalware (ai score=81)
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/Glupteba!ml
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2259406
ZoneAlarmBackdoor.Win32.Androm.uirx
GDataTrojan.GenericKD.36017158
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R362183
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34742.nmKfa0j9QXoG
ALYacTrojan.SmokeLoader
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HIOX
TrendMicro-HouseCallTROJ_GEN.R067C0DA921
TencentWin32.Backdoor.Androm.Pdlw
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.HIFA!tr
AVGWin32:DropperX-gen [Drp]
AvastWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Backdoor.e53

How to remove Backdoor.Win32.Androm.uirx?

Backdoor.Win32.Androm.uirx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment