Trojan

Should I remove “TrojanDownloader:Win32/Andromeda!pz”?

Malware Removal

The TrojanDownloader:Win32/Andromeda!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Andromeda!pz virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Andromeda!pz?


File Info:

name: 9F68421069F72133E245.mlw
path: /opt/CAPEv2/storage/binaries/882e1d971827364bbe412deaf5270b551f2054d7d346f4be8207fe79a98e4aab
crc32: DC3FA967
md5: 9f68421069f72133e2459cf444245020
sha1: 49377d3b6062e01b67c6d35993e1fab8bf19f3e5
sha256: 882e1d971827364bbe412deaf5270b551f2054d7d346f4be8207fe79a98e4aab
sha512: 7d11b34dbf87a84c265e1454a4351d7980e6d7a7f0fe18d5ec82f7c8353ec50e0a231f08838e14977966a64ee249f06aa50cfa6465ea2b477af2e0c5f1e54b85
ssdeep: 96:nEY2RrF1eqwi4c4Kr/pClDhALywtERXDCxxHwAxoeknh2v:EHRh1eppar/ewywDxDv
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T110E19E07D577C561F83FF9BA2F1F0B9AA2B944C5A97E1E7200F24E0915B0148E285B9F
sha3_384: 0bbd8019436895111b6090368d97821f7a9a46f57cfce6be364073e553472882125feff6d4383066b6d4164fa9279182
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-05-23 11:25:12

Version Info:

0: [No Data]

TrojanDownloader:Win32/Andromeda!pz also known as:

BkavW32.FamVT.DebrisA.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.63208
FireEyeGeneric.mg.9f68421069f72133
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Worm.xz
McAfeeW32/Worm-FKH!9F68421069F7
MalwarebytesBundpil.Worm.AutoRun.DDS
ZillyaWorm.DebrisGen.Win32.1
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0040f7ba1 )
K7AntiVirusTrojan ( 0040f7ba1 )
ArcabitTrojan.Barys.DF6E8
BaiduWin32.Worm.Bundpil.an
VirITWorm.Win32.Generic.FXU
SymantecDownloader
tehtrisGeneric.Malware
ESET-NOD32Win32/Bundpil.AH
APEXMalicious
ClamAVWin.Adware.Downware-493
KasperskyWorm.Win32.Debris.h
BitDefenderGen:Variant.Barys.63208
NANO-AntivirusTrojan.Win32.Debris.cssocy
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Debris-A [Wrm]
TACHYONWorm/W32.Debris.7119.B
SophosTroj/Agent-ACCV
GoogleDetected
F-SecureWorm.WORM/Debris.J.1
DrWebWorm.Siggen.12242
VIPREGen:Variant.Barys.63208
TrendMicroWORM_GAMARUE.SMA
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Barys.63208 (B)
IkarusWorm.Win32.Debris
JiangminWorm/Debris.a
WebrootW32.Worm.Gen
VaristW32/Csyr.B.gen!Eldorado
AviraWORM/Debris.J.1
Antiy-AVLWorm/Win32.Debris
Kingsoftmalware.kb.a.997
XcitiumWorm.Win32.Bundpil.AH@4yjufs
MicrosoftTrojanDownloader:Win32/Andromeda!pz
ZoneAlarmWorm.Win32.Debris.h
GDataGen:Variant.Barys.63208
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Debris.R68969
Acronissuspicious
BitDefenderThetaGen:NN.ZedlaF.36802.aq5@aWbSzHn
ALYacGen:Variant.Barys.63208
MAXmalware (ai score=81)
VBA32Worm.Gamarue
Cylanceunsafe
PandaW32/Autorun.KAB.worm
TrendMicro-HouseCallWORM_GAMARUE.SMA
RisingWorm.Gamarue!1.9CB3 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.Debris.k
FortinetW32/Agent.AF!worm
AVGWin32:Debris-A [Wrm]
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Andromeda!pz?

TrojanDownloader:Win32/Andromeda!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment