Trojan

About “TrojanDownloader:Win32/Andromeda!pz” infection

Malware Removal

The TrojanDownloader:Win32/Andromeda!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Andromeda!pz virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Andromeda!pz?


File Info:

name: 6A94D7846FBE42F8637F.mlw
path: /opt/CAPEv2/storage/binaries/9cbc54753f1ceab5124c1eeccbbb7ab606dc0eedda70a90687f8971c55815098
crc32: 61B6ED9E
md5: 6a94d7846fbe42f8637fa59d75491bcc
sha1: 07777d98ed3cb09f4824d4ce6c28f9539e53c06b
sha256: 9cbc54753f1ceab5124c1eeccbbb7ab606dc0eedda70a90687f8971c55815098
sha512: 08c4cb6778c7315c1cb088af0fd827fe45ca123815b88be7fae1dd31ee5d37b79d0c2e39a46c169331d8669bb750135df932bfcc5dfddbe82d7f16a6d6824fa7
ssdeep: 96:nEY2RrF1eqwi41ymBOak5lN2+OiuPxwrHu+VH:EHRh1epp1EL1Oimx
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1B2D174462356CFBBEE444BF1DD5A0049F08AEC2DED794A72A3430B113AF0E9D59E5B11
sha3_384: ea7a132f3e626454abf7d9f00129dc9edfc7e221dfe88fb0b1cf8652661aab5e12c2b8b60c080ed335b186accf5647f7
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-05-23 11:25:12

Version Info:

0: [No Data]

TrojanDownloader:Win32/Andromeda!pz also known as:

BkavW32.FamVT.DebrisA.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.63208
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Worm.xz
McAfeeW32/Worm-FKH!6A94D7846FBE
MalwarebytesBundpil.Worm.AutoRun.DDS
VIPREGen:Variant.Barys.63208
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0040f7ba1 )
K7GWTrojan ( 0040f7ba1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Worm.Bundpil.an
VirITWorm.Win32.Generic.FXU
SymantecDownloader
tehtrisGeneric.Malware
ESET-NOD32Win32/Bundpil.AH
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Adware.Downware-493
KasperskyWorm.Win32.Debris.h
BitDefenderGen:Variant.Barys.63208
NANO-AntivirusTrojan.Win32.Debris.cssocy
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Debris-A [Wrm]
TencentWorm.Win32.Debris.a
SophosTroj/Agent-ACCV
F-SecureWorm.WORM/Debris.J.1
DrWebWorm.Siggen.12242
ZillyaWorm.DebrisGen.Win32.1
TrendMicroWORM_GAMARUE.SMA
EmsisoftGen:Variant.Barys.63208 (B)
IkarusWorm.Win32.Debris
JiangminWorm/Debris.a
WebrootW32.Worm.Gen
VaristW32/Csyr.B.gen!Eldorado
AviraWORM/Debris.J.1
Antiy-AVLWorm/Win32.Debris
Kingsoftmalware.kb.a.997
MicrosoftTrojanDownloader:Win32/Andromeda!pz
XcitiumWorm.Win32.Bundpil.AH@4yjufs
ArcabitTrojan.Barys.DF6E8
ZoneAlarmWorm.Win32.Debris.h
GDataGen:Variant.Barys.63208
GoogleDetected
AhnLab-V3Worm/Win32.Debris.R68969
Acronissuspicious
BitDefenderThetaGen:NN.ZedlaF.36680.aq5@aWbSzHn
ALYacGen:Variant.Barys.63208
TACHYONWorm/W32.Debris.6482.B
VBA32Worm.Gamarue
Cylanceunsafe
PandaW32/Autorun.KAB.worm
TrendMicro-HouseCallWORM_GAMARUE.SMA
RisingWorm.Gamarue!1.9CB3 (CLASSIC)
YandexTrojan.GenAsa!BiSnwDyq9yo
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.Debris.k
FortinetW32/Agent.AF!worm
AVGWin32:Debris-A [Wrm]
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Andromeda!pz?

TrojanDownloader:Win32/Andromeda!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment