Backdoor

Backdoor.Win32.Androm.ujbb malicious file

Malware Removal

The Backdoor.Win32.Androm.ujbb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.ujbb virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Maori
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Androm.ujbb?


File Info:

crc32: 01E3B2A2
md5: 665d88a5643e259303e1021c68c8f054
name: 665D88A5643E259303E1021C68C8F054.mlw
sha1: cc40589938ac2ac3bb0ae9d996aebcc3fb5849f3
sha256: 0b9555e73d90f0ff2506c001b5fed2e986f74e8e988cc1a4a8dc0e1dd377113b
sha512: b7370cb75c641506f149bd28710df4884886504428d16dde0bd75ef4c309c0657c7829802235ffa743ae708895e6267c3389298ab0a9ca27aba55d93af4824ae
ssdeep: 6144:oTntptRXM8S9pZjDKpDh5xsyRS12j2AT92G:ItXRc8SP+jsoSI2k2G
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalSurname: vebuk.ekc
Prod: 1.2.8
FileVersions: 1.0.5.9
LegalCo: Copyri (C) 2019, pirmudationca

Backdoor.Win32.Androm.ujbb also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36109361
McAfeeArtemis!665D88A5643E
MalwarebytesTrojan.MalPack.GS
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 005762ae1 )
BitDefenderTrojan.GenericKD.36109361
K7GWTrojan ( 005762ae1 )
ArcabitTrojan.Generic.D226FC31
CyrenW32/Trojan.ACPV-5829
SymantecTrojan.Gen.MBT
APEXMalicious
KasperskyBackdoor.Win32.Androm.ujbb
AlibabaBackdoor:Win32/Androm.3c1e0419
TencentWin32.Backdoor.Androm.Wnwn
Ad-AwareTrojan.GenericKD.36109361
EmsisoftTrojan.Crypt (A)
ComodoTrojWare.Win32.UMal.hmwge@0
F-SecureTrojan.TR/AD.Behavior.pxvkf
DrWebTrojan.DownLoader36.35049
TrendMicroTROJ_FRS.VSNW0FA21
McAfee-GW-EditionBehavesLike.Win32.Trojan.dc
FireEyeGeneric.mg.665d88a5643e2593
SophosMal/Generic-S + Troj/Agent-BGJF
IkarusTrojan.Win32.Crypt
WebrootW32.Trojan.Gen
AviraTR/AD.Behavior.pxvkf
MAXmalware (ai score=87)
KingsoftWin32.Hack.Androm.uj.(kcloud)
GridinsoftTrojan.Win32.Packed.oa
MicrosoftTrojan:Win32/Zenpack!ml
ViRobotTrojan.Win32.Z.Zenpack.218624
ZoneAlarmBackdoor.Win32.Androm.ujbb
GDataWin32.Trojan-Downloader.SmokeLoader.R4GGLW
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R362952
Acronissuspicious
ALYacTrojan.GenericKD.36109361
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HITY
TrendMicro-HouseCallTROJ_FRS.VSNW0FA21
RisingTrojan.Kryptik!8.8 (TFE:5:Q0vcaijwEJU)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.GWXD!tr
BitDefenderThetaGen:NN.ZexaF.34760.nmGfa0EqHUoG
AVGFileRepMalware
AvastFileRepMalware
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.c96

How to remove Backdoor.Win32.Androm.ujbb?

Backdoor.Win32.Androm.ujbb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment