Trojan

Should I remove “TrojanDownloader:Win32/Andromeda!pz”?

Malware Removal

The TrojanDownloader:Win32/Andromeda!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Andromeda!pz virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Andromeda!pz?


File Info:

name: 0FF1FB79F0222B5F4414.mlw
path: /opt/CAPEv2/storage/binaries/070d5c46ef96df17c1e7ad78501207db500a0d58f06d0757bc5af37b7658d228
crc32: 0D2FE55D
md5: 0ff1fb79f0222b5f4414af9c2999ca4b
sha1: 25dac625346db53496ac5c9937993c37e2234e6a
sha256: 070d5c46ef96df17c1e7ad78501207db500a0d58f06d0757bc5af37b7658d228
sha512: efede7d6c37bdd6a8bff9a3922b2b13a6cefcdfdcce8b53bf3dbc31a50c6940f18775c0b4f3959228f192a4b23dd71004543c2acc8bcb77cc0429cf7bc58db2d
ssdeep: 96:nEY2RrF1eqwi4tjnP4/4+7KQEdfF3VmUmpfX:EHRh1epp5nA/4+7Kn9JV4
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1F0C11F83E2574A53FD0407B99E0F888B68EF982BFDB01955F1CC0B10799808C7BEAD95
sha3_384: 56b2ae917a6e593de8002dd8feb16aa171be4d41f414934bc898fce0a21e36529b25d4c0aa6bf67e5053403086b83571
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-05-23 11:25:12

Version Info:

0: [No Data]

TrojanDownloader:Win32/Andromeda!pz also known as:

BkavW32.FamVT.DebrisA.Worm
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.0ff1fb79f0222b5f
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Worm.xz
McAfeeW32/Worm-FKH!0FF1FB79F022
MalwarebytesBundpil.Worm.AutoRun.DDS
VIPREGen:Variant.Barys.63208
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0040f7ba1 )
K7GWTrojan ( 0040f7ba1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Barys.DF6E8
BaiduWin32.Worm.Bundpil.an
VirITWorm.Win32.Generic.FXU
SymantecDownloader
tehtrisGeneric.Malware
ESET-NOD32Win32/Bundpil.AH
APEXMalicious
ClamAVWin.Adware.Downware-493
KasperskyWorm.Win32.Debris.h
BitDefenderGen:Variant.Barys.63208
NANO-AntivirusTrojan.Win32.Debris.cssocy
MicroWorld-eScanGen:Variant.Barys.63208
AvastWin32:Debris-A [Wrm]
TACHYONWorm/W32.Debris.6146.B
EmsisoftGen:Variant.Barys.63208 (B)
F-SecureWorm.WORM/Debris.J.1
DrWebWorm.Siggen.12242
ZillyaWorm.DebrisGen.Win32.1
TrendMicroWORM_GAMARUE.SMA
Trapminemalicious.high.ml.score
SophosTroj/Agent-ACCV
IkarusWorm.Win32.Debris
JiangminWorm/Debris.a
WebrootW32.Worm.Gen
GoogleDetected
AviraWORM/Debris.J.1
Antiy-AVLWorm/Win32.Debris
Kingsoftmalware.kb.a.998
XcitiumWorm.Win32.Bundpil.AH@4yjufs
MicrosoftTrojanDownloader:Win32/Andromeda!pz
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmWorm.Win32.Debris.h
GDataGen:Variant.Barys.63208
VaristW32/Csyr.B.gen!Eldorado
AhnLab-V3Worm/Win32.Debris.R68969
Acronissuspicious
BitDefenderThetaGen:NN.ZedlaF.36744.aq5@aWbSzHn
MAXmalware (ai score=89)
VBA32Worm.Gamarue
Cylanceunsafe
PandaW32/Autorun.KAB.worm
TrendMicro-HouseCallWORM_GAMARUE.SMA
RisingWorm.Gamarue!1.9CB3 (CLASSIC)
YandexTrojan.GenAsa!BiSnwDyq9yo
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.Debris.k
FortinetW32/Agent.AF!worm
AVGWin32:Debris-A [Wrm]
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Andromeda!pz?

TrojanDownloader:Win32/Andromeda!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment