Backdoor

Backdoor.Win32.Androm.utkt removal instruction

Malware Removal

The Backdoor.Win32.Androm.utkt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.utkt virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
pomf.lain.la

How to determine Backdoor.Win32.Androm.utkt?


File Info:

crc32: 4925EE30
md5: ecc32f34e2f7dd3142a79941b96d67f0
name: ECC32F34E2F7DD3142A79941B96D67F0.mlw
sha1: 327fac8f44f2499bb94242791bd902d4f952adc8
sha256: 13cd902db4c2d83cf33f2d2ab048f048126f7152a8e549fa31f5deeb4f2f0294
sha512: 8e3aeba2c3f643f5ea9e650588863092eab264852abdffe8263948d953a8ea697bf953949ef784efabb955aa8fe230a206616400aed4db87d44524764ec549a1
ssdeep: 6144:I4XrK9PX7Fp6Gh2wWRGl0EDDf1PisZQ5rAGQwg1QtP1f4paaYlsdcaMJEdbI0Pz:XXe9PPlowWX0t6mOQwg1Qd15CcYk0We
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0809 0x04b0

Backdoor.Win32.Androm.utkt also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Androm.m!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
Cybereasonmalicious.f44f24
CyrenW32/AutoIt.UX.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32Win32/TrojanDownloader.Autoit.PET
APEXMalicious
AvastWin32:Trojan-gen
KasperskyBackdoor.Win32.Androm.utkt
BitDefenderTrojan.GenericKD.37512553
MicroWorld-eScanTrojan.GenericKD.37512553
TencentMalware.Win32.Gencirc.10cecbe6
Ad-AwareTrojan.GenericKD.37512553
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.ecc32f34e2f7dd31
EmsisoftTrojan.GenericKD.37512553 (B)
WebrootW32.Trojan.GenKD
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Script/Phonzy.C!ml
GDataWin32.Trojan.PSE.JCXCHA
AhnLab-V3Trojan/Win.Generic.C4609845
McAfeeArtemis!ECC32F34E2F7
MAXmalware (ai score=85)
MalwarebytesMalware.AI.891801861
IkarusTrojan.Autoit
FortinetAutoIt/Injector.BFC6!tr
AVGWin32:Trojan-gen

How to remove Backdoor.Win32.Androm.utkt?

Backdoor.Win32.Androm.utkt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment