Backdoor

About “Andromeda.Backdoor.Downloader.DDS” infection

Malware Removal

The Andromeda.Backdoor.Downloader.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Andromeda.Backdoor.Downloader.DDS virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Executed a process and injected code into it, probably while unpacking
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
morphed.ru
amnsreiuojy.ru

How to determine Andromeda.Backdoor.Downloader.DDS?


File Info:

crc32: 34DF16B8
md5: 0221e8977a5dacb7fd64369dac66b0f2
name: 0221E8977A5DACB7FD64369DAC66B0F2.mlw
sha1: aacf518f8cfdeb8cfd4f6862bfdeca5bb8026eaa
sha256: b6d0d191be9969d5a415aa2987c6b599bb2264c0fdff9887778a2a4aa5768f6c
sha512: f02d1d963362043b805428d70f64841f7eac8c0e75c11574b5906edb7250d4a5c78e668507f713cec29a9cd0201f286811ba9218daaf0f82e10f494f067caa81
ssdeep: 768:dUSWvIZoY5EkjdIMKJtoqWTwXJzw18bEzVmvvkkIhsQZsNUfygDQyHqil+nAWeoQ:SDYxdIrJMTwZc+GsvvT4i4p515o7bL69
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright Misejkaxa9 2013
InternalName: Ragiza
FileVersion: 2, 1, 3, 2
CompanyName: Hause
PrivateBuild: Kizbow
LegalTrademarks: Giokaxa9
Comments: Gezera
ProductName: Bigalov
SpecialBuild: Makanz
ProductVersion: 5, 1, 8, 4
FileDescription: Mikega
OriginalFilename: Magez
Translation: 0x0409 0x04b0

Andromeda.Backdoor.Downloader.DDS also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Downloader.251
ClamAVWin.Malware.Gamarue-7001972-0
FireEyeGeneric.mg.0221e8977a5dacb7
CAT-QuickHealWorm.Gamarue.B
ALYacGen:Variant.Downloader.251
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan-Downloader ( 0056a5f91 )
BitDefenderGen:Variant.Downloader.251
K7GWTrojan-Downloader ( 0056a5f91 )
Cybereasonmalicious.77a5da
BaiduWin32.Trojan-Downloader.Wauchos.a
CyrenW32/Gamarue.C.gen!Eldorado
SymantecSMG.Heur!gen
TotalDefenseWin32/Gamarue.EBeAEVC
TrendMicro-HouseCallWORM_GAMARUE.SMJ
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyWorm.Win32.Bundpil.aws
AlibabaWorm:Win32/Bundpil.4a95903d
NANO-AntivirusTrojan.Win32.Andromeda.csstqi
ViRobotTrojan.Win32.Agent.1689890
TencentTrojan.Win32.Injector.h
Ad-AwareGen:Variant.Downloader.251
SophosML/PE-A + Mal/Inject-EA
ComodoTrojWare.Win32.Kryptik.BBYD@4y3c16
F-SecureTrojan-Downloader:W32/Wauchos.F
DrWebBackDoor.Andromeda.178
VIPRETrojan.Win32.Inject.ea (v)
TrendMicroWORM_GAMARUE.SMJ
McAfee-GW-EditionGeneric.gl.gen.a
EmsisoftGen:Variant.Downloader.251 (B)
IkarusTrojan.SuspectCRC
JiangminBackdoor/Androm.mi
AviraTR/Dropper.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan[Dropper]/Win32.Injector
MicrosoftWorm:Win32/Gamarue.I
ArcabitTrojan.Downloader.251
SUPERAntiSpywareTrojan.Agent/Gen-Symmi
ZoneAlarmWorm.Win32.Bundpil.aws
GDataGen:Variant.Downloader.251
AhnLab-V3Dropper/Win32.Injector.R79295
McAfeeGeneric.gl.gen.a
VBA32Backdoor.Androm
MalwarebytesAndromeda.Backdoor.Downloader.DDS
PandaTrj/Genetic.gen
APEXMalicious
ESET-NOD32Win32/TrojanDownloader.Wauchos.L
RisingWorm.Gamarue!1.A224 (CLASSIC)
YandexTrojan.GenAsa!tycDiK8FwtU
SentinelOneStatic AI – Suspicious PE – Downloader
FortinetW32/Kryptik.BBYD!tr
BitDefenderThetaGen:NN.ZexaF.34804.Mr2@a4YRpOdO
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Botnet.Andromeda.HgIASOMA

How to remove Andromeda.Backdoor.Downloader.DDS?

Andromeda.Backdoor.Downloader.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment