Trojan

Should I remove “TrojanDownloader:Win32/Andromeda!pz”?

Malware Removal

The TrojanDownloader:Win32/Andromeda!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Andromeda!pz virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Andromeda!pz?


File Info:

name: DFC4208D444D4C5FFC27.mlw
path: /opt/CAPEv2/storage/binaries/8ee5d7a2d4da9912edbedd4fb08c32ade7a74829faf4c9612ea08ea6417a42f5
crc32: 2754E8F3
md5: dfc4208d444d4c5ffc27ae8bdbc87056
sha1: 7c99ff6865520acfbe8623e581b896570e091c10
sha256: 8ee5d7a2d4da9912edbedd4fb08c32ade7a74829faf4c9612ea08ea6417a42f5
sha512: 0b6d44d7096d4687881d144aeadda35d307e252d2f937dfe965bc3e6bf16a76d15a0649b1f03f1e6a1ccf65c635d205a4417feae10729ae55917939844e57691
ssdeep: 96:nEY2RrF1eqwi4PEBQfOPGoXezm9JL2bcM5M4:EHRh1eppcBQfGhqWd2xe4
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T18BD19E0F46729A62FE584FFE5E0D08D265CBB845FDE12534A24A0AC427D019EB5EDE32
sha3_384: 88e15615b8c7d6071393a192d6fb166179f2ac55418fa4fef667f7189adc2b536566ba127188dd602b73d2d53e1fb014
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-05-23 11:25:12

Version Info:

0: [No Data]

TrojanDownloader:Win32/Andromeda!pz also known as:

BkavW32.FamVT.DebrisA.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.63208
ClamAVWin.Adware.Downware-493
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Worm.xz
McAfeeW32/Worm-FKH!DFC4208D444D
MalwarebytesBundpil.Worm.AutoRun.DDS
VIPREGen:Variant.Barys.63208
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0040f7ba1 )
K7AntiVirusTrojan ( 0040f7ba1 )
BaiduWin32.Worm.Bundpil.an
VirITWorm.Win32.Generic.FXU
SymantecDownloader
ESET-NOD32Win32/Bundpil.AH
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Debris.h
BitDefenderGen:Variant.Barys.63208
NANO-AntivirusTrojan.Win32.Debris.cssocy
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Debris-A [Wrm]
EmsisoftGen:Variant.Barys.63208 (B)
F-SecureWorm.WORM/Debris.J.1
DrWebWorm.Siggen.12242
ZillyaWorm.DebrisGen.Win32.1
TrendMicroWORM_GAMARUE.SMA
FireEyeGeneric.mg.dfc4208d444d4c5f
SophosTroj/Agent-ACCV
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.63208
JiangminWorm/Debris.a
WebrootW32.Worm.Gen
GoogleDetected
AviraWORM/Debris.J.1
MAXmalware (ai score=82)
Antiy-AVLWorm/Win32.Debris
Kingsoftmalware.kb.a.997
XcitiumWorm.Win32.Bundpil.AH@4yjufs
ArcabitTrojan.Barys.DF6E8
ZoneAlarmWorm.Win32.Debris.h
MicrosoftTrojanDownloader:Win32/Andromeda!pz
VaristW32/Csyr.B.gen!Eldorado
AhnLab-V3Worm/Win32.Debris.R68969
Acronissuspicious
BitDefenderThetaGen:NN.ZedlaF.36744.aq5@aWbSzHn
ALYacGen:Variant.Barys.63208
TACHYONWorm/W32.Debris.6258
VBA32Worm.Gamarue
Cylanceunsafe
PandaW32/Autorun.KAB.worm
TrendMicro-HouseCallWORM_GAMARUE.SMA
RisingWorm.Gamarue!1.9CB3 (CLASSIC)
IkarusWorm.Win32.Debris
MaxSecureWorm.Debris.k
FortinetW32/Agent.AF!worm
AVGWin32:Debris-A [Wrm]
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Andromeda!pz?

TrojanDownloader:Win32/Andromeda!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment