Trojan

Should I remove “TrojanDownloader:Win32/Andromeda!pz”?

Malware Removal

The TrojanDownloader:Win32/Andromeda!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Andromeda!pz virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Andromeda!pz?


File Info:

name: F8EE2973304CA8AA04DC.mlw
path: /opt/CAPEv2/storage/binaries/9ec011a14071b5bb366373128341ef4bfbfe50c0c987ef4bf0104dfe32024ad2
crc32: 42B4EDAB
md5: f8ee2973304ca8aa04dcd98e2807c340
sha1: 9647034214583f3b888c4763c4076e3de303e701
sha256: 9ec011a14071b5bb366373128341ef4bfbfe50c0c987ef4bf0104dfe32024ad2
sha512: c2ab4a7ed2deb42767cae016bc8d7c2c4ed90e5a54f67aaadf10b6311493bcff127a0b8f7e694b950bebd200d0e205542338bfd8b37484679acd7548324602cd
ssdeep: 96:hy859x0P8MaRpXNj68uAYTKnmh2LfrvzoXnP3I5gqnCkl:F5oLWxu6PzsPYnCkl
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T16DE1230AD662C4A0DE2C96FB5E0E5C9B39EB4815FDB83E65B0CC044811D444DBFDEEA6
sha3_384: fd3426e364a2d4c170e5a786a05914af21a0499c7cc4356f60ba6119fceb7916a56336bb3e452ee30d52c94eb2b00c1d
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-06-12 12:49:36

Version Info:

0: [No Data]

TrojanDownloader:Win32/Andromeda!pz also known as:

BkavW32.FamVT.DebrisA.Worm
tehtrisGeneric.Malware
DrWebTrojan.MulDrop4.25343
MicroWorld-eScanGen:Variant.Barys.63208
ClamAVWin.Adware.Downware-251
FireEyeGeneric.mg.f8ee2973304ca8aa
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Worm.xt
McAfeeW32/Worm-FJV!F8EE2973304C
MalwarebytesBundpil.Worm.AutoRun.DDS
ZillyaWorm.DebrisGen.Win32.11
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
K7GWEmailWorm ( 0040f5281 )
K7AntiVirusEmailWorm ( 0040f5281 )
ArcabitTrojan.Barys.DF6E8
BitDefenderThetaGen:NN.ZedlaF.36744.aq5@ae9rVOn
VirITWorm.Win32.Generic.GRN
SymantecDownloader.Dromedan
Elasticmalicious (high confidence)
ESET-NOD32Win32/Bundpil.AO
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Debris.b
BitDefenderGen:Variant.Barys.63208
NANO-AntivirusTrojan.Win32.Debris.cqkxyu
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
AvastWin32:Sg-I [Trj]
RisingWorm.Gamarue!1.9CB3 (CLASSIC)
SophosW32/Gamarue-BL
F-SecureWorm.WORM/Gamarue.511265
BaiduWin32.Worm.Bundpil.y
VIPREGen:Variant.Barys.63208
TrendMicroWORM_GAMARUE.SML
EmsisoftGen:Variant.Barys.63208 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.axdgt
WebrootW32.Worm.Gen
GoogleDetected
AviraWORM/Gamarue.511265
MAXmalware (ai score=82)
Antiy-AVLWorm/Win32.Debris
Kingsoftmalware.kb.a.997
XcitiumWorm.Win32.Bundpil.AH@4yjufs
MicrosoftTrojanDownloader:Win32/Andromeda!pz
ZoneAlarmWorm.Win32.Debris.b
GDataWin32.Worm.Bundpil.B
VaristW32/Csyr.B.gen!Eldorado
AhnLab-V3Worm/Win32.Debris.R71328
VBA32Worm.Gamarue
ALYacGen:Variant.Barys.63208
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallWORM_GAMARUE.SML
TencentWorm.Win32.Debris.c
IkarusWorm.Win32.Bundpil
MaxSecureWorm.Debris.Gen
FortinetW32/Bundpil.AO!tr
AVGWin32:Sg-I [Trj]
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Andromeda!pz?

TrojanDownloader:Win32/Andromeda!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment