Backdoor

VHO:Backdoor.Win32.Androm removal

Malware Removal

The VHO:Backdoor.Win32.Androm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Backdoor.Win32.Androm virus can do?

  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine VHO:Backdoor.Win32.Androm?


File Info:

crc32: 92790B06
md5: 96b8866e34b1318069c72bc03323811d
name: 96B8866E34B1318069C72BC03323811D.mlw
sha1: 38782c7edd806fc7635f90b24a38261a3f837861
sha256: 4a0c5bd60c7c83b6166b73a5128541a3ef025ebeb054d2eb5056a54ced4a24f1
sha512: 6a58f81556b91ac26c9deacfcfe7021ea3e7f5e949ca251fab302e0e0a44a71140052f0f7821bfaf3380696e437d1cc7772666a24384739af800e596aff01fc7
ssdeep: 49152:el3ANmgKBUPOfuOIAHU2HSVOgDDGTYi7yB9k10BIGGBmDXlchNyR4F/:e9AcgKBUK4anHwZu4B98GwmDGvyR
type: PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Microsoft
Assembly Version: 0.0.0.0
InternalName: activation.exe
FileVersion: 11.0.1.1
CompanyName: Microsoft
LegalTrademarks: Microsoft
Comments: SVC Memory Compression
ProductName: SVC Memory Compression
ProductVersion: 11.0.1.1
FileDescription: SVC Memory Compression
OriginalFilename: activation.exe

VHO:Backdoor.Win32.Androm also known as:

Elasticmalicious (high confidence)
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
ESET-NOD32a variant of MSIL/CoinMiner.BIP
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Backdoor.Win32.Androm.gen
SophosML/PE-A
FireEyeGeneric.mg.96b8866e34b13180
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1101701
eGambitUnsafe.AI_Score_100%
MicrosoftProgram:Win32/Wacapew.C!ml
MalwarebytesMalware.AI.4079208026

How to remove VHO:Backdoor.Win32.Androm?

VHO:Backdoor.Win32.Androm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment