Trojan

TrojanDownloader:Win32/Andromeda!pz removal instruction

Malware Removal

The TrojanDownloader:Win32/Andromeda!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Andromeda!pz virus can do?

  • Authenticode signature is invalid
  • Binary file triggered YARA rule
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDownloader:Win32/Andromeda!pz?


File Info:

name: 46521E5D5A203294C9AD.mlw
path: /opt/CAPEv2/storage/binaries/6d924e2c8d101936b3bfb113e2b84da170b300dc9264f67c530eaa162fbc79c0
crc32: 7F4CBDD0
md5: 46521e5d5a203294c9ad40cc7faf66fc
sha1: 20e33ed4ffa3df0538592105c700beae3ab601e4
sha256: 6d924e2c8d101936b3bfb113e2b84da170b300dc9264f67c530eaa162fbc79c0
sha512: 52e72c996e2d9fe8d9ae50564a817c3a5f8af7762c1fdf90daff1f2b75d7aa80d078b2b20c87ed94997c089862b2c7a8ad4ad81f89b96f11a450f4ef6def3fb2
ssdeep: 48:qfAqMrhWR69rDvrXkxLVYuX/2svystYVzwG4RApL5:FlrY6JrrXk3vbduVzwG4+5
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T123711F3B3699EEB3C1A8237526E7179D709EAF35436342C74281852E546D2A07FF3B11
sha3_384: e4aacc322ab0d4adf73ccc56444058430346c6524a1974761fcfe204f2ed657de13ebf20be4ba6504e4b73c6eae4f49b
ep_bytes: 558bec518b450c8945fcb8010000008b
timestamp: 2013-07-01 21:53:27

Version Info:

0: [No Data]

TrojanDownloader:Win32/Andromeda!pz also known as:

BkavW32.FamVT.DebrisA.Worm
LionicWorm.Win32.Debris.lNQC
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop4.25343
MicroWorld-eScanGen:Variant.Zusy.325289
FireEyeGeneric.mg.46521e5d5a203294
CAT-QuickHealTrojan.Agent.WL
SkyhighDownloader-FOB!46521E5D5A20
McAfeeDownloader-FOB!46521E5D5A20
MalwarebytesWorm.Gamarue
VIPREGen:Variant.Zusy.325289
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f52e1 )
BitDefenderGen:Variant.Zusy.325289
K7GWTrojan ( 0040f52e1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Zusy.D4F6A9
BitDefenderThetaGen:NN.ZedlaF.36744.aq4@a4DzT!h
VirITWorm.Win32.Generic.HHB
SymantecW32.Dromedan
ESET-NOD32a variant of Win32/Bundpil.BC
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Adware.Downware-242
KasperskyWorm.Win32.Debris.aq
AlibabaWorm:Win32/Debris.0e61b141
NANO-AntivirusTrojan.Win32.Drop.bxprxw
ViRobotTrojan.Win32.Agent.3584.AZ
RisingWorm.Gamarue!1.9CC6 (CLASSIC)
SophosW32/Gamarue-BJ
F-SecureWorm.WORM/Gamarue.358495
BaiduWin32.Worm.Agent.q
ZillyaWorm.DebrisGen.Win32.2
TrendMicroWORM_GAMARUE.SMF
EmsisoftGen:Variant.Zusy.325289 (B)
SentinelOneStatic AI – Malicious PE
JiangminWorm/Debris.am
WebrootW32.Worm.Gen
VaristW32/Csyr.C.gen!Eldorado
AviraWORM/Gamarue.358495
MAXmalware (ai score=89)
Antiy-AVLWorm/Win32.Debris.aq
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.Bundpil.BL@4zjaeb
MicrosoftTrojanDownloader:Win32/Andromeda!pz
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
ZoneAlarmWorm.Win32.Debris.aq
GDataGen:Variant.Zusy.325289
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R73096
Acronissuspicious
VBA32Worm.Gamarue
ALYacGen:Variant.Zusy.325289
TACHYONWorm/W32.Debris.3584.G
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Vilsel.AF
TrendMicro-HouseCallWORM_GAMARUE.SMF
TencentWorm.Win32.Debris.b
IkarusWin32.Outbreak
FortinetW32/Bundpil.AA!tr
AVGWin32:Sg-C [Trj]
AvastWin32:Sg-C [Trj]

How to remove TrojanDownloader:Win32/Andromeda!pz?

TrojanDownloader:Win32/Andromeda!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment