Backdoor

Backdoor:Win32/Androm.VAM!MTB removal instruction

Malware Removal

The Backdoor:Win32/Androm.VAM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Androm.VAM!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Androm.VAM!MTB?


File Info:

crc32: E5283C9E
md5: c98abe403d21f4249de8c92a1cd0a79c
name: C98ABE403D21F4249DE8C92A1CD0A79C.mlw
sha1: fc833855144fdd29d691784f17149b6f4eabf081
sha256: a6e4d566693de23d4e9a169b765d509c634451cbb24b61ed498a593e7163ed1c
sha512: 3efa6a42b0f573a6e36aaa1cb12c6a2158ed2020d2483ddfc25ed32907e30838d189dbbf9ec5fb64538afcdb9f6ce7d0145b62f23c6d61989489b8789b3f753d
ssdeep: 768:j8KhjM02mH0K++PODLpq1EVo6VPnrKMugobH:zhqmHU+yLU1OtHw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Logical Yegar
InternalName: DATADELEFLAG
FileVersion: 1.00
CompanyName: Yegar
LegalTrademarks: Logical Yegar
Comments: Yegar
ProductName: Yegar
ProductVersion: 1.00
FileDescription: Yegar
OriginalFilename: DATADELEFLAG.exe

Backdoor:Win32/Androm.VAM!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.352897
FireEyeGeneric.mg.c98abe403d21f424
McAfeeRDN/packed-ftb
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Bulz.352897
K7GWTrojan ( 00577aee1 )
K7AntiVirusTrojan ( 00577aee1 )
CyrenW32/Kryptik.DCA.gen!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Vebzenpak.adpw
AlibabaTrojan:Win32/Vebzenpak.6d1d441a
TencentWin32.Trojan.Vebzenpak.Szve
Ad-AwareGen:Variant.Bulz.352897
EmsisoftGen:Variant.Bulz.352897 (B)
F-SecureHeuristic.HEUR/AGEN.1133790
DrWebTrojan.VbCrypt.2064
TrendMicroTROJ_FRS.0NA103BC21
McAfee-GW-EditionRDN/packed-ftb
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1133790
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftBackdoor:Win32/Androm.VAM!MTB
GridinsoftTrojan.Win32.Agent.oa
ArcabitTrojan.Bulz.D56281
ZoneAlarmTrojan.Win32.Vebzenpak.adpw
GDataGen:Variant.Bulz.352897
CynetMalicious (score: 90)
AhnLab-V3Malware/Win32.RL_Generic.R366143
BitDefenderThetaGen:NN.ZevbaF.34804.dm0@a4C4cPh
ALYacGen:Variant.Bulz.352897
MAXmalware (ai score=83)
MalwarebytesTrojan.MalPack.VB
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EONT
TrendMicro-HouseCallTROJ_FRS.0NA103BC21
RisingTrojan.Injector!8.C4 (CLOUD)
SentinelOneStatic AI – Suspicious PE
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Backdoor:Win32/Androm.VAM!MTB?

Backdoor:Win32/Androm.VAM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment