Backdoor

About “Backdoor.Win32.Androm.uqbc” infection

Malware Removal

The Backdoor.Win32.Androm.uqbc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.uqbc virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Unconventionial language used in binary resources: Czech
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Androm.uqbc?


File Info:

crc32: 61ED30AE
md5: e079ebb471a7db52fa456af14440d58d
name: E079EBB471A7DB52FA456AF14440D58D.mlw
sha1: a7c3b75d04dd91fb5b51d0786dab2a29455d1265
sha256: 97e8e53c9ad758050c08da0cf14f7024dba1d7710b0f612f13d2b5a458dd13bb
sha512: 7052b123151bdc3b3f8d8d5b8a6b89c88534eea65e256cbba42733c3f0643458b3f1ba9c5a6255083c8de1b3dc15e277d50ad6159a7c0c40ade834385aeaa6f4
ssdeep: 3072:ZuVV2YGvaFMvA2Oydgkvl5LsEOkKoea5UFzMYTul:8tYa2vtOyRvl5LsEOkKoeSUFzil
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0405 0x04b0
InternalName: Antecessor
FileVersion: 1.00
CompanyName: Muddy ADMO Calc
Comments: Muddy ADMO Calc
ProductName: Muddy ADMO Calc
ProductVersion: 1.00
FileDescription: Muddy ADMO Calc
OriginalFilename: Antecessor.exe

Backdoor.Win32.Androm.uqbc also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0057e5c91 )
Elasticmalicious (high confidence)
DrWebTrojan.PackedENT.228
CynetMalicious (score: 100)
ALYacBackdoor.Androm.gen
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaBackdoor:Win32/VBObfuse.df4b486a
K7GWTrojan ( 0057e5c91 )
Cybereasonmalicious.d04dd9
CyrenW32/VBKrypt.AWF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EPOH
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyBackdoor.Win32.Androm.uqbc
BitDefenderGen:Variant.Razy.880943
MicroWorld-eScanGen:Variant.Razy.880943
Ad-AwareGen:Variant.Razy.880943
SophosMal/Generic-S
ComodoMalware@#3eet86vcr57nu
BitDefenderThetaGen:NN.ZevbaF.34758.lm1@a4i1axeG
TrendMicroTROJ_GEN.R06CC0DFN21
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.e079ebb471a7db52
EmsisoftGen:Variant.Razy.880943 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Injector.vkoff
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/VBObfuse.SS!MTB
ArcabitTrojan.Razy.DD712F
AegisLabTrojan.Win32.Androm.m!c
GDataGen:Variant.Razy.880943
AhnLab-V3Trojan/Win.VBObfuse.R426937
McAfeeGenericRXAA-AA!E079EBB471A7
MAXmalware (ai score=86)
VBA32TScope.Trojan.VB
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R06CC0DFN21
RisingTrojan.Injector!1.D771 (CLASSIC)
IkarusTrojan.VB.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.EPOH!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml

How to remove Backdoor.Win32.Androm.uqbc?

Backdoor.Win32.Androm.uqbc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment