Backdoor

Backdoor.Win32.Androm.uqbe removal

Malware Removal

The Backdoor.Win32.Androm.uqbe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.uqbe virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Unconventionial language used in binary resources: Czech
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Androm.uqbe?


File Info:

crc32: CD722398
md5: aa2bd93add61460d059367e41d89195c
name: AA2BD93ADD61460D059367E41D89195C.mlw
sha1: 9368ee245f899583bdc97ad8e13f4b02b09dbe38
sha256: 7f347545daf832b84a0cb2d823af46e874cb7c69f436814c58355262e594c4d3
sha512: 7701741099368b2cd3346bcc25aee27ee4a30036c94719a37b3dba22a86fab87b3b718aff7fa6f7c2375254fa0c99fd6b28f8e484f010e4f5d14057dcca083ff
ssdeep: 3072:HYwQ0Fm09ZcwQv1kRunskawj2YyQLKbWM3lYp+:4J5wTRunskHj2YyQLKbWLp+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0405 0x04b0
InternalName: Loamiest7
FileVersion: 1.00
CompanyName: Muddy ADMO Calc
Comments: Muddy ADMO Calc
ProductName: Muddy ADMO Calc
ProductVersion: 1.00
FileDescription: Muddy ADMO Calc
OriginalFilename: Loamiest7.exe

Backdoor.Win32.Androm.uqbe also known as:

K7AntiVirusTrojan ( 0057e5c91 )
Elasticmalicious (high confidence)
DrWebTrojan.PackedENT.228
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.880943
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/VBObfuse.818ad510
K7GWTrojan ( 0057e5c91 )
Cybereasonmalicious.45f899
CyrenW32/VBKrypt.AWF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EPOH
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyBackdoor.Win32.Androm.uqbe
BitDefenderGen:Variant.Razy.880943
MicroWorld-eScanGen:Variant.Razy.880943
Ad-AwareGen:Variant.Razy.880943
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZevbaF.34758.lm1@aqqIQkhG
TrendMicroTROJ_GEN.R06CC0DFN21
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.aa2bd93add61460d
EmsisoftGen:Variant.Razy.880943 (B)
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Hack.Androm.uq.(kcloud)
MicrosoftTrojan:Win32/VBObfuse.SS!MTB
ArcabitTrojan.Razy.DD712F
AegisLabWorm.Win32.WBVB.o!c
GDataGen:Variant.Razy.880943
AhnLab-V3Trojan/Win.VBObfuse.R426937
McAfeeGenericRXAA-AA!AA2BD93ADD61
MAXmalware (ai score=86)
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R06CC0DFN21
RisingTrojan.Injector!1.D771 (CLASSIC)
IkarusTrojan.VB.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.EPOH!tr
AVGWin32:DangerousSig [Trj]

How to remove Backdoor.Win32.Androm.uqbe?

Backdoor.Win32.Androm.uqbe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment