Trojan

About “TrojanDownloader:Win32/Andromeda!pz” infection

Malware Removal

The TrojanDownloader:Win32/Andromeda!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Andromeda!pz virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Andromeda!pz?


File Info:

name: 0467DA94E4CF27241AF8.mlw
path: /opt/CAPEv2/storage/binaries/845b311b7e4c38c81135a3c2e25bc072b2bece53aff1f15a3f6b5c1344e81449
crc32: FC039DD0
md5: 0467da94e4cf27241af869918e8d3660
sha1: 479d762470ef4a55d3562b7de245c89496669ba4
sha256: 845b311b7e4c38c81135a3c2e25bc072b2bece53aff1f15a3f6b5c1344e81449
sha512: f6581ba849ab120a40d55ac77a83d3fccb1079392fab2eabdcb76a57ba11266a5ab57df53d56615c216694eb833d8a292d544f2b50edfb25df7110e5c82113ca
ssdeep: 96:nEY2RrF1eqwi4oZgKsO+vhMNrWyNlrFaAruFF6WVl:EHRh1eppoCKP+GtWyrB1uFF6Wz
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1A3D14A479B77CA21EC3AD97B031E0A8393B94CD1746C99F640F95B1292500D8A35AF7B
sha3_384: a328852805b3b472e66fac428c634dbc9ab0945f5f1c4f19b866e7b9d80925eae937183ece3af04164e0f139c11b2c3e
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-05-23 11:25:12

Version Info:

0: [No Data]

TrojanDownloader:Win32/Andromeda!pz also known as:

BkavW32.FamVT.DebrisA.Worm
tehtrisGeneric.Malware
DrWebWorm.Siggen.12242
MicroWorld-eScanGen:Variant.Barys.63208
ClamAVWin.Adware.Downware-493
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Worm.xz
McAfeeW32/Worm-FKH!0467DA94E4CF
MalwarebytesBundpil.Worm.AutoRun.DDS
VIPREGen:Variant.Barys.63208
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0040f7ba1 )
K7GWTrojan ( 0040f7ba1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Barys.DF6E8
BitDefenderThetaGen:NN.ZedlaF.36680.aq5@aWbSzHn
VirITWorm.Win32.Generic.FXU
SymantecDownloader
Elasticmalicious (high confidence)
ESET-NOD32Win32/Bundpil.AH
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Debris.h
BitDefenderGen:Variant.Barys.63208
NANO-AntivirusTrojan.Win32.Debris.cssocy
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Debris-A [Wrm]
TencentWorm.Win32.Debris.a
EmsisoftGen:Variant.Barys.63208 (B)
F-SecureWorm.WORM/Debris.J.1
BaiduWin32.Worm.Bundpil.an
ZillyaWorm.DebrisGen.Win32.1
TrendMicroWORM_GAMARUE.SMA
SophosTroj/Agent-ACCV
IkarusWorm.Win32.Debris
JiangminWorm/Debris.a
WebrootW32.Worm.Gen
GoogleDetected
AviraWORM/Debris.J.1
Antiy-AVLWorm/Win32.Debris
Kingsoftmalware.kb.a.997
XcitiumWorm.Win32.Bundpil.AH@4yjufs
MicrosoftTrojanDownloader:Win32/Andromeda!pz
ZoneAlarmWorm.Win32.Debris.h
GDataGen:Variant.Barys.63208
VaristW32/Csyr.B.gen!Eldorado
AhnLab-V3Worm/Win32.Debris.R68969
Acronissuspicious
ALYacGen:Variant.Barys.63208
TACHYONWorm/W32.Debris.6622.D
VBA32Worm.Gamarue
Cylanceunsafe
PandaW32/Autorun.KAB.worm
TrendMicro-HouseCallWORM_GAMARUE.SMA
RisingWorm.Gamarue!1.9CB3 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.Debris.k
FortinetW32/Agent.AF!worm
AVGWin32:Debris-A [Wrm]
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Andromeda!pz?

TrojanDownloader:Win32/Andromeda!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment