Backdoor

What is “Backdoor.Win32.Androm.upxt”?

Malware Removal

The Backdoor.Win32.Androm.upxt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.upxt virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Unconventionial language used in binary resources: Czech
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Androm.upxt?


File Info:

crc32: A1884F31
md5: af95cba60a0fd16678f0df73d9dcc1b7
name: AF95CBA60A0FD16678F0DF73D9DCC1B7.mlw
sha1: 5453c2cf3ef88a19247ceef6e2eed3abbe8bc004
sha256: c03b5d783971f4ab3ae3dac1b9576acfc0334cd919ffd74bb6ac01cbef2b128d
sha512: ce52c2dbe7f6607bae8d1e054b0bb7e0e53223bd1f9f6686afa538e5d598d19e41c14afbec949773b32a3f343be7f09852d58bc5a6b5abb81f76172642fd7e1b
ssdeep: 3072:RTk3TZNosPnTfZlkqBkSMGaysAVzdYTGgy1RnkCK83+TtjL:tWfomn36SMGaysAVzdYTzy1l9MV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0405 0x04b0
InternalName: koprino
FileVersion: 1.00
CompanyName: Muddy ADMO Calc
Comments: Muddy ADMO Calc
ProductName: Muddy ADMO Calc
ProductVersion: 1.00
FileDescription: Muddy ADMO Calc
OriginalFilename: koprino.exe

Backdoor.Win32.Androm.upxt also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0057e5c91 )
Elasticmalicious (high confidence)
DrWebTrojan.PackedENT.228
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.880943
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojan:Win32/VBObfuse.28b6149a
K7GWTrojan ( 0057e5c91 )
CyrenW32/VBKrypt.AWF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EPOH
APEXMalicious
AvastWin32:Malware-gen
KasperskyBackdoor.Win32.Androm.upxt
BitDefenderGen:Variant.Razy.880943
MicroWorld-eScanGen:Variant.Razy.880943
Ad-AwareGen:Variant.Razy.880943
BitDefenderThetaGen:NN.ZevbaF.34758.lm1@ayD@YjgG
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.af95cba60a0fd166
EmsisoftGen:Variant.Razy.880943 (B)
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_100%
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/VBObfuse.SS!MTB
ArcabitTrojan.Razy.DD712F
GDataGen:Variant.Razy.880943
AhnLab-V3Trojan/Win.VBObfuse.R426937
McAfeeGenericRXAA-AA!AF95CBA60A0F
MAXmalware (ai score=82)
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R06CH09FM21
IkarusTrojan.VB.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.EPOH!tr
AVGWin32:Malware-gen

How to remove Backdoor.Win32.Androm.upxt?

Backdoor.Win32.Androm.upxt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment