Trojan

How to remove “TrojanDownloader:Win32/Andromeda!pz”?

Malware Removal

The TrojanDownloader:Win32/Andromeda!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Andromeda!pz virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Andromeda!pz?


File Info:

name: 19D599E86B67615C4D03.mlw
path: /opt/CAPEv2/storage/binaries/027719e462dbc5d138dbc48cf6b9c2ffc0cbefb2a93d25f0fcb8db73239e35e1
crc32: 8BF751EB
md5: 19d599e86b67615c4d03c412ada9883d
sha1: d63b670bf953251588489abf4793f9b943859e17
sha256: 027719e462dbc5d138dbc48cf6b9c2ffc0cbefb2a93d25f0fcb8db73239e35e1
sha512: 7ec2f3c09085b1fdffa57a6b33ebe06aaaa0030db6bb09698862e4aa2113b4b00bfefbbc3d0a36952c64477603dd478bd1598378a3961354d9581c30bd0a083c
ssdeep: 96:nEY2RrF1eqwi4ht9COprwHN5p86KKS3W:EHRh1eppAIrCNEKSm
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T114B112AB9769EDB3CC0A4BFF4B0E18A1B45FCE7695F0C9B142CB075529206AC5E50F81
sha3_384: c72776754a58ba987d5da1d0217554be88365ad18c8b377ea86fb1d1bdb7d64b5dba3ca2788196de821e5626621690b9
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-05-23 11:25:12

Version Info:

0: [No Data]

TrojanDownloader:Win32/Andromeda!pz also known as:

BkavW32.FamVT.DebrisA.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.431082
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Worm.zz
McAfeeW32/Worm-FKH!19D599E86B67
MalwarebytesBundpil.Worm.AutoRun.DDS
ZillyaWorm.DebrisGen.Win32.1
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0040f7ba1 )
K7AntiVirusTrojan ( 0040f7ba1 )
ArcabitTrojan.Barys.D693EA
BitDefenderThetaGen:NN.ZedlaF.36680.aq5@aWbSzHn
VirITWorm.Win32.Generic.FXU
SymantecDownloader
tehtrisGeneric.Malware
ESET-NOD32Win32/Bundpil.AH
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Adware.Downware-493
KasperskyWorm.Win32.Debris.h
BitDefenderGen:Variant.Barys.431082
NANO-AntivirusTrojan.Win32.Debris.cssocy
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Debris-A [Wrm]
TencentWorm.Win32.Debris.a
EmsisoftGen:Variant.Barys.431082 (B)
BaiduWin32.Worm.Bundpil.an
F-SecureWorm.WORM/Debris.J.1
DrWebWorm.Siggen.12242
VIPREGen:Variant.Barys.431082
TrendMicroWORM_GAMARUE.SMA
SophosTroj/Agent-ACCV
IkarusWorm.Win32.Debris
JiangminWorm/Debris.a
WebrootW32.Worm.Gen
VaristW32/Csyr.B.gen!Eldorado
AviraWORM/Debris.J.1
Antiy-AVLWorm/Win32.Debris
Kingsoftmalware.kb.a.995
XcitiumWorm.Win32.Bundpil.AH@4yjufs
MicrosoftTrojanDownloader:Win32/Andromeda!pz
ZoneAlarmWorm.Win32.Debris.h
GDataGen:Variant.Barys.431082
GoogleDetected
AhnLab-V3Worm/Win32.Debris.R68969
Acronissuspicious
ALYacGen:Variant.Barys.431082
TACHYONWorm/W32.Debris.5446.E
VBA32Worm.Gamarue
Cylanceunsafe
PandaW32/Autorun.KAB.worm
TrendMicro-HouseCallWORM_GAMARUE.SMA
RisingWorm.Gamarue!1.9CB3 (CLASSIC)
YandexTrojan.GenAsa!BiSnwDyq9yo
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.Debris.k
FortinetW32/Agent.AF!worm
AVGWin32:Debris-A [Wrm]
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Andromeda!pz?

TrojanDownloader:Win32/Andromeda!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment