Backdoor

How to remove “Backdoor.Win32.Androm.uryy”?

Malware Removal

The Backdoor.Win32.Androm.uryy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.uryy virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Androm.uryy?


File Info:

crc32: 80D3BF61
md5: 110674843d5db859484ec85f8dc258ff
name: 110674843D5DB859484EC85F8DC258FF.mlw
sha1: be7439fbf7940223c6cac80b036cbe5763a8ba28
sha256: a8311b50a5b93ff1c9424d9c483b9d23c3105cf13c91d8decf08dc477a05ce2c
sha512: 7eeec2fb3b3f1bc420d8b3dfdf282065c3281a08ab64699a9087e19abe420589137e6a36338ccebcb0652a14e9558ee7d78f8e0ebdd05848fbc2dc3c6dad67bd
ssdeep: 98304:lJcUQLUGrupb8ECl7hvVF3VHbo0TR9OYGacjTCAUUfKFlpQbdUXawZnRyP4VmZqK:HPGZKb8EoNvVFlHbPXOgQGAUK4QbS5u7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Setup Engine Copyright xa9 2004-2018 Indigo Rose Corporation
InternalName: suf_launch
FileVersion: 9.5.2.0
LegalTrademarks: Setup Factory is a trademark of Indigo Rose Corporation.
Comments: Created with Setup Factory
ProductName: Setup Factory Runtime
ProductVersion: 9.5.2.0
FileDescription: Setup Application
OriginalFilename: suf_launch.exe
Translation: 0x0409 0x04e4

Backdoor.Win32.Androm.uryy also known as:

LionicTrojan.Win32.Androm.m!c
DrWebTrojan.Gozi.825
ClamAVWin.Malware.Ursu-9854581-0
ALYacTrojan.GenericKD.46774322
CylanceUnsafe
AlibabaBackdoor:Win32/Androm.bbb46a58
K7GWTrojan ( 00580e8b1 )
K7AntiVirusTrojan ( 00580e8b1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/GenCBL.ARN
AvastWin32:Trojan-gen
CynetMalicious (score: 99)
KasperskyBackdoor.Win32.Androm.uryy
BitDefenderTrojan.GenericKD.46774322
NANO-AntivirusTrojan.Win32.Androm.izpbum
MicroWorld-eScanTrojan.GenericKD.46774322
Ad-AwareTrojan.GenericKD.46774322
SophosMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.46774322
EmsisoftMalCert-S.LH (A)
AviraBDS/Androm.upcwl
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Ymacco.ABA8
ArcabitTrojan.Generic.D2C9B832
ZoneAlarmBackdoor.Win32.Androm.uryy
GDataTrojan.GenericKD.46774322
McAfeeArtemis!110674843D5D
MAXmalware (ai score=85)
VBA32Backdoor.Androm
TrendMicro-HouseCallTROJ_GEN.R002H0CHC21
RisingTrojan.MalCert!1.D8A6 (CLASSIC)
IkarusTrojan.Win32.Generic
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Androm.URYY!tr.bdr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Backdoor.Win32.Androm.uryy?

Backdoor.Win32.Androm.uryy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment