Malware

Generic.Andromeda.D1F0A090 (file analysis)

Malware Removal

The Generic.Andromeda.D1F0A090 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Andromeda.D1F0A090 virus can do?

  • Executable code extraction
  • Unconventionial language used in binary resources: Hindi
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Andromeda.D1F0A090?


File Info:

crc32: F8D00DF0
md5: aa5a0192da49a9f7e02535928a3c5887
name: AA5A0192DA49A9F7E02535928A3C5887.mlw
sha1: 9ca6875292f7da4bc38f29c0f49c01e7d372389c
sha256: a1f5a0c59a23378af7c7d8bbc0c16d1af460af82a6850e27945cabe4a20614fc
sha512: 2e38f95ea402819ad313e4b1f6c4d7c2cea359b85cfece173c1988b574354965806705909f20ab949ce9df13aaafecf56c312dfd873f675f79f7f008c4d8fc1d
ssdeep: 1536:Tfq8TJmm/g4dEmXw6JiU/qt9p29K9huydsP/QWNU+ZTKe/uanAR2buS:T1TJB/g4f9iDte9KjuydtW2sBu2Ad
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic.Andromeda.D1F0A090 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Propagate.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen8.16331
ALYacDeepScan:Generic.Andromeda.D1F0A090
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Propagate.e45a6361
K7GWTrojan ( 00549cb51 )
K7AntiVirusTrojan ( 00549cb51 )
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GQWA
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Propagate.izi
BitDefenderDeepScan:Generic.Andromeda.D1F0A090
NANO-AntivirusTrojan.Win32.Chapak.fnztxs
MicroWorld-eScanDeepScan:Generic.Andromeda.D1F0A090
TencentWin32.Trojan.Propagate.Lneg
Ad-AwareDeepScan:Generic.Andromeda.D1F0A090
SophosMal/Generic-S + Mal/GandCrab-G
ComodoMalware@#ch365597adqz
BitDefenderThetaGen:NN.ZexaF.34142.hmGfa4CBi2bG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.aa5a0192da49a9f7
EmsisoftDeepScan:Generic.Andromeda.D1F0A090 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Gimemo.wr
AviraHEUR/AGEN.1119074
Antiy-AVLTrojan/Generic.ASMalwS.2ADD8D6
MicrosoftPWS:Win32/Fareit.P!MTB
ArcabitDeepScan:Generic.Andromeda.D1F0A090
ZoneAlarmTrojan.Win32.Propagate.izi
GDataDeepScan:Generic.Andromeda.D1F0A090
AhnLab-V3Trojan/Win32.RansomCrypt.R258745
Acronissuspicious
McAfeeArtemis!AA5A0192DA49
MAXmalware (ai score=100)
VBA32BScope.Trojan.Diple
MalwarebytesRansom.GandCrab
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B677 (CLASSIC)
YandexTrojan.Propagate!czfzFRyYMeo
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GQVU!tr.ransom
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Generic.Andromeda.D1F0A090?

Generic.Andromeda.D1F0A090 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment