Threat Database Trojans Trojan.Andromeda

Trojan.Andromeda

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 1,487
Threat Level: 80 % (High)
Infected Computers: 70,806
First Seen: January 16, 2013
Last Seen: December 11, 2025
OS(es) Affected: Windows

SpyHunter Detects & Remove Trojan.Andromeda

File System Details

Trojan.Andromeda may create the following file(s):
# File Name MD5 Detections
1. temp2924814056.exe 12224b26a4621d48c5b14b3ef59d677e 252
2. temp325040394.exe 7df8d128456318415b6da7babdda2da9 111
3. ccpneudb.scr b034f422ca749d7f437dadd6793150a9 60
4. temp2530652380.exe cdab5e84205d8780e3f3937deba00aee 42
5. temp2368817904.exe 7b82352cab21783225a2e4adc10372e5 32
6. msusia.exe 58813340f64d8fb3d2c9eb979a7c1789 28
7. ccswdb.exe ec62d054a4c985a1692026e0ae03f9c4 27
8. temp4070005724.exe a7e2fee0619d516415cc8d168bb87815 26
9. ccyyhqvc.com 6b8127ac97a215ef0d33ca414b32c098 25
10. temp1523121008.exe 597d39e4e83a1b9c73fdf13669bfd060 24
11. ccraukcas.exe a7a578066f965cd2690e379feefe3008 23
12. Roaming/cppredistx86.exe 51ebf4ba41cf212b8b204014170f7a74 21
13. ccinoy.exe 4e4248ffb4f0fe25ecc4c5311f656828 18
14. msuwybt.com 0b459f0b0d947595b4a671dddf815b66 18
15. temp2592084110.exe eb2b8e97e1afbd9bcd91c781fd30fafe 18
16. cchayar.bat 3d57c8d21282f2788eb3db832bebdc1a 16
17. ccrzouca.bat 18e8dd34e2ed80572cdc78e327c24d29 16
18. cctmzwavu.pif bc2bb280235e1ded6deed08ea4dac91a 14
19. ccyilayi.pif c0362c9322ebbdf88cb91385d2f6a821 12
20. temp1893493066.exe 0bdb2ba4619467fd6c2a6f80423de1a8 12
21. ccyauaq.bat 51debec08573433e2555f0062d12f9cc 7
22. ccoqixp.bat ff137df1eaa514ff5dea3555a78c7dc0 6
23. buddypress.exe ca806b09ee4f1eb5cf0846a556fbb1f3 4
24. Roaming/Microsoft/Skype.exe 536e46d1fcfeb3469c5b2e2bda475e95 4
25. Roaming/microsoft/windows/usernet.exe fb8da7a72c10ba72fbdc2c1acc93f7fd 3
26. roaming/microsoft/network/connections/hostsvcdl.exe 7e165b5bf1e57c2129ab093b95e1aaa7 2
27. file.exe 16f553bf68aca4b0bfb8bcf9ab1929d7 1
More files

Registry Details

Trojan.Andromeda may create the following registry entry or registry entries:
Regexp file mask
%APPDATA%\Microsoft\Skype.exe
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\filename.vbs
%LOCALAPPDATA%\teamviever_tr.exe
%temp%\temp[NUMBERS].exe
%Windir%\Skypee\skypee.exe
%WINDIR%\System32\Tasks\alFSVWJB
%WINDIR%\Tasks\alFSVWJB.job
Software\alFSVWJB
Software\Microsoft\Windows\CurrentVersion\Run\action_extend
SOFTWARE\Microsoft\Windows\CurrentVersion\Run\buddy-telephone

Directories

Trojan.Andromeda may create the following directory or directories:

%APPDATA%\Buddy_witness
%APPDATA%\alFSVWJB
%LOCALAPPDATA%\Action-tend

Trending

Most Viewed

Loading...