Threat Database Trojans Trojan.Andromeda

Trojan.Andromeda

By CagedTech in Trojans

Threat Scorecard

Ranking: 3,060
Threat Level: 80 % (High)
Infected Computers: 69,837
First Seen: January 16, 2013
Last Seen: March 6, 2024
OS(es) Affected: Windows

SpyHunter Detects & Remove Trojan.Andromeda

File System Details

Trojan.Andromeda may create the following file(s):
# File Name MD5 Detections
1. temp2924814056.exe 12224b26a4621d48c5b14b3ef59d677e 252
2. temp325040394.exe 7df8d128456318415b6da7babdda2da9 111
3. temp2530652380.exe cdab5e84205d8780e3f3937deba00aee 42
4. temp2368817904.exe 7b82352cab21783225a2e4adc10372e5 32
5. msusia.exe 58813340f64d8fb3d2c9eb979a7c1789 28
6. ccswdb.exe ec62d054a4c985a1692026e0ae03f9c4 27
7. temp4070005724.exe a7e2fee0619d516415cc8d168bb87815 26
8. temp1523121008.exe 597d39e4e83a1b9c73fdf13669bfd060 24
9. Roaming/cppredistx86.exe 51ebf4ba41cf212b8b204014170f7a74 21
10. msuwybt.com 0b459f0b0d947595b4a671dddf815b66 18
11. temp2592084110.exe eb2b8e97e1afbd9bcd91c781fd30fafe 18
12. file.exe dd158dc92052758519df867e586350d0 18
13. ccrzouca.bat 18e8dd34e2ed80572cdc78e327c24d29 16
14. cctmzwavu.pif bc2bb280235e1ded6deed08ea4dac91a 14
15. temp1893493066.exe 0bdb2ba4619467fd6c2a6f80423de1a8 12
16. buddypress.exe ca806b09ee4f1eb5cf0846a556fbb1f3 4
17. Roaming/Microsoft/Skype.exe 501aeb91abc596455a25cda8f890c951 4
18. Roaming/Microsoft/Skype.exe 536e46d1fcfeb3469c5b2e2bda475e95 4
19. Roaming/microsoft/windows/usernet.exe fb8da7a72c10ba72fbdc2c1acc93f7fd 3
20. Roaming/Microsoft/Skype.exe d1a9e636d8dd04fe7f22d852438be468 2
21. Roaming/Microsoft/Skype.exe ce6ba3df1d57ade7830c5315d77c9311 2
22. roaming/microsoft/network/connections/hostsvcdl.exe 7e165b5bf1e57c2129ab093b95e1aaa7 2
23. File.exe 2d1aed40c355c4fe9f3ccb1be052860b 1
24. Roaming/Microsoft/Skype.exe 3944e996c7850c70106fe075175aee3a 1
25. Roaming/Microsoft/Skype.exe 8199fd767ee618b4fc8944a8c4b6f2f4 1
26. Roaming/Microsoft/Skype.exe 854225196ad95331c30757e7cf16d741 1
27. Roaming/Microsoft/Skype.exe 4896cc35c1b232693a71ee6954abec77 1
28. file.exe 02c8cf7aadb0587bed422f70d3847ccf 0
29. file.exe 16f553bf68aca4b0bfb8bcf9ab1929d7 0
More files

Registry Details

Trojan.Andromeda may create the following registry entry or registry entries:
Regexp file mask
%APPDATA%\Microsoft\Skype.exe
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\filename.vbs
%LOCALAPPDATA%\teamviever_tr.exe
%temp%\temp[NUMBERS].exe
%Windir%\Skypee\skypee.exe
%WINDIR%\System32\Tasks\alFSVWJB
%WINDIR%\Tasks\alFSVWJB.job
Software\alFSVWJB
Software\Microsoft\Windows\CurrentVersion\Run\action_extend
SOFTWARE\Microsoft\Windows\CurrentVersion\Run\buddy-telephone

Directories

Trojan.Andromeda may create the following directory or directories:

%APPDATA%\Buddy_witness
%APPDATA%\alFSVWJB
%LOCALAPPDATA%\Action-tend

Trending

Most Viewed

Loading...