Backdoor

How to remove “Backdoor.Win32.Androm.vpnw”?

Malware Removal

The Backdoor.Win32.Androm.vpnw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Androm.vpnw virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to modify browser security settings
  • Accessed credential storage registry keys
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor.Win32.Androm.vpnw?


File Info:

name: ABE213B4EE4527094194.mlw
path: /opt/CAPEv2/storage/binaries/e40f9ff3dda096f79746566f7a3d596dc596abb064cd639fa5534248884afd7f
crc32: 759CB136
md5: abe213b4ee4527094194ecfae4a767e8
sha1: 7f715501c27a5b3129bff868f7783b48ac241b22
sha256: e40f9ff3dda096f79746566f7a3d596dc596abb064cd639fa5534248884afd7f
sha512: 7195240455756a087955a71af4274205cd24e724c7eb69d6501c96673b9bde73e1003d58317abcd89a7975a4ee95f6aeb586aebf735d9fc135418119d405fe0e
ssdeep: 24576:XdZKo0YNGSQDlUHSLFD7XX2yyjXdbNxD7E:XTK6ESQmSLFfX5+NhxD7E
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16B15CE3972F0A371D875053227E4D2385AE86F68CEE1C74BD2B01A99B320DD53E6865F
sha3_384: 384ba571ad4b2fa4673cea3576820c162e9e09a27ffb6c0602ab785ef5e76fdf72e8039177fce7555a12a0e52fee8798
ep_bytes: e815060000e978feffffe9cf3c000055
timestamp: 2021-10-07 11:14:54

Version Info:

0: [No Data]

Backdoor.Win32.Androm.vpnw also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Androm.m!c
MicroWorld-eScanTrojan.GenericKD.71614123
McAfeeRDN/loki
Cylanceunsafe
VIPRETrojan.GenericKD.71614123
SangforBackdoor.Win32.Androm.Va22
BitDefenderTrojan.GenericKD.71614123
Cybereasonmalicious.4ee452
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32Win32/PSW.Fareit.L
APEXMalicious
ClamAVWin.Trojan.Mikey-9839945-0
KasperskyBackdoor.Win32.Androm.vpnw
AlibabaBackdoor:Win32/Fareit.4a523a76
NANO-AntivirusTrojan.Win32.TrjGen.kimfvs
RisingMalware.Obfus/MSIL@AI.86 (RDM.MSIL2:wP02O9AsMgLjHkcdil2PAg)
BitDefenderThetaGen:NN.ZemsilCO.36744.pm0@amG3TB
ZillyaTrojan.Diztakun.Win32.8171
TrendMicroTROJ_GEN.R002C0PBE24
FireEyeGeneric.mg.abe213b4ee452709
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Uztuby
AviraTR/Dropper.MSIL.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/MSIL.Androm
KingsoftWin32.Troj.Generic.v
XcitiumMalware@#s54arouvnd2i
ArcabitTrojan.Generic.D444BEAB
ViRobotTrojan.Win.Z.Uztuby.935848
ZoneAlarmBackdoor.Win32.Androm.vpnw
GDataTrojan.GenericKD.71614123
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Meterpreter.C5104322
VBA32Backdoor.DarkKomet
ALYacTrojan.GenericKD.71614123
MalwarebytesSpyware.LokiBot
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0PBE24
TencentWin32.Backdoor.Androm.Qsmw
YandexTrojan.Agent!JcoglBBSV9k
IkarusTrojan.Agent
MaxSecureTrojan.Malware.232548377.susgen
FortinetW32/PossibleThreat
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.Win32.Androm.vpnw?

Backdoor.Win32.Androm.vpnw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment