Trojan

How to remove “TrojanDownloader:Win32/Andromeda!pz”?

Malware Removal

The TrojanDownloader:Win32/Andromeda!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Andromeda!pz virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Andromeda!pz?


File Info:

name: A682ACBB8B6FA819AEDA.mlw
path: /opt/CAPEv2/storage/binaries/bc6d838195150633d87cc02f275d5f9f54f7e5245b5a58c2285ce035b5d05915
crc32: 4ED82B45
md5: a682acbb8b6fa819aedab0eb7aa01a3f
sha1: a9f0b121b39f7e3eb1ddf71bb43a9b7599160d0a
sha256: bc6d838195150633d87cc02f275d5f9f54f7e5245b5a58c2285ce035b5d05915
sha512: 3f398c3af259b43ab9db23a8f0930b9609ac644f2425e62130e19a4e997fb10833428a56e771d6a1a6ff42bfd1cd811aa79db3a9c7d199b5dff1af9e57f75cd0
ssdeep: 96:hy859x0P8MaJsb6LKWCzozl3zBqO0htI5iDsfhrL:F5oL2sbCjCzohjfbcs
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1F8C1F00E47734461DD28F6FE6B1F9CC269FB288599B52C78918C194C932049DBF8EFA1
sha3_384: 8b077dbe676a1e00b30bf89a4a543725bcb5c19191ce72e56371cf6d9a45408692cfd029dc4dde20aecd8e9c6885a5cb
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-06-12 12:49:36

Version Info:

0: [No Data]

TrojanDownloader:Win32/Andromeda!pz also known as:

BkavW32.FamVT.DebrisA.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.381598
FireEyeGeneric.mg.a682acbb8b6fa819
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Worm.zt
McAfeeW32/Worm-FJV!A682ACBB8B6F
MalwarebytesBundpil.Worm.AutoRun.DDS
ZillyaWorm.DebrisGen.Win32.11
SangforSuspicious.Win32.Save.ins
K7AntiVirusEmailWorm ( 0040f5281 )
K7GWEmailWorm ( 0040f5281 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZedlaF.36802.aq5@ae9rVOn
VirITWorm.Win32.Generic.GRN
SymantecDownloader.Dromedan
tehtrisGeneric.Malware
ESET-NOD32Win32/Bundpil.AO
APEXMalicious
TrendMicro-HouseCallWORM_GAMARUE.SML
ClamAVWin.Adware.Downware-251
KasperskyWorm.Win32.Debris.b
BitDefenderGen:Variant.Barys.381598
NANO-AntivirusTrojan.Win32.Debris.cqkxyu
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
AvastWin32:Sg-I [Trj]
TencentWorm.Win32.Debris.c
SophosW32/Gamarue-BL
BaiduWin32.Worm.Bundpil.y
F-SecureWorm.WORM/Gamarue.511265
DrWebTrojan.MulDrop4.25343
VIPREGen:Variant.Barys.381598
TrendMicroWORM_GAMARUE.SML
EmsisoftGen:Variant.Barys.381598 (B)
IkarusWorm.Win32.Bundpil
JiangminTrojan/Generic.axdgt
WebrootW32.Worm.Gen
GoogleDetected
AviraWORM/Gamarue.511265
VaristW32/Csyr.B.gen!Eldorado
Antiy-AVLWorm/Win32.Debris
Kingsoftmalware.kb.a.998
MicrosoftTrojanDownloader:Win32/Andromeda!pz
XcitiumWorm.Win32.Bundpil.AH@4yjufs
ArcabitTrojan.Barys.D5D29E
ZoneAlarmWorm.Win32.Debris.b
GDataWin32.Worm.Bundpil.B
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Debris.R71328
VBA32Worm.Gamarue
MAXmalware (ai score=85)
Cylanceunsafe
PandaGeneric Malware
RisingWorm.Gamarue!1.9CB3 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.Debris.Gen
FortinetW32/Bundpil.AO!tr
AVGWin32:Sg-I [Trj]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Gamarue.66c7f521

How to remove TrojanDownloader:Win32/Andromeda!pz?

TrojanDownloader:Win32/Andromeda!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment