BackDoor.Andromeda
Posted: May 24, 2012
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
Threat Level: | 6/10 |
---|---|
Infected PCs: | 7,935 |
First Seen: | May 24, 2012 |
---|---|
Last Seen: | June 26, 2019 |
OS(es) Affected: | Windows |
BackDoor.Andromeda is a backdoor Trojan that was identified by reputable PC security companies in late 2011. As is the case with other backdoor Trojans, BackDoor.Andromeda foremost goal is to infect your PC secretly and drill a vulnerability through its security that permits criminals to take over your PC from a remote server. BackDoor.Andromeda may also be used to install other PC threats such as Trojan.Hosts.5858, distribute itself via removable media or even steal passwords from FTP programs. As an intricate PC threat that includes traits of worms and spyware along with its backdoor Trojan attacks, BackDoor.Andromeda should be deleted as soon as you can do so, although SpywareRemove.com malware researchers preferentially recommend the use of anti-malware applications for this purpose.
All the Signs Point to BackDoor.Andromeda Being a Bad Omen for Your Computer
BackDoor.Andromeda is distributed as an .exe file that's usually named in a misleading manner; for example, 'DHL ticket.exe' (to make you think that BackDoor.Andromeda is related to airline booking issues), 'BBB report.exe' (referencing the Better Business Bureau) or 'IMG9231.jpg.exe' (a fake picture file). While these types of fraudulent files are often distributed in spam e-mail messages and social networking links, they can also be distributed via other methods. After being launched, BackDoor.Andromeda will make efforts to set up itself on your PC and on any removable media devices such as USB thumb drives. Accordingly, SpywareRemove.com malware experts discourage sharing USB drives and similar devices with other computers until you've removed BackDoor.Andromeda completely, since BackDoor.Andromeda can easily infect any other PC that shares the device via Autorun.inf exploits.
Perhaps BackDoor.Andromeda's most serious attack is its ability to connect to a remote C&C server, from which BackDoor.Andromeda may download other PC threats for installation or transfer personal information over to criminals. Backdoor vulnerabilities like those that are caused by BackDoor.Andromeda infections should always be considered high-level security and privacy risks.
A Run Through BackDoor.Andromeda's Stealth Routines
As part of its default behavior, BackDoor.Andromeda can conceal its files with hidden flags, particularly with respect to removable hard drives. Since there may not be any visible signs of BackDoor.Andromeda's attacks, you should be ready to use dedicated anti-malware programs to detect all components of BackDoor.Andromeda (along with any other types of hostile software that BackDoor.Andromeda could have downloaded and installed).
Expelling BackDoor.Andromeda should be of particular concern for users of FTP programs, since SpywareRemove.com malware researchers have found that BackDoor.Andromeda is designed to steal WinSCP passwords from the Registry. However, unlike true spyware, BackDoor.Andromeda hasn't been found to include keylogging or other types of broad information-stealing attacks that could be used to violate other types of information - although BackDoor.Andromeda may install different PC threats that are capable of such feats.
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:C:\Users\<username>\AppData\Local\6e745dw6rg7t8itu.exe
File name: 6e745dw6rg7t8itu.exeSize: 696.32 KB (696320 bytes)
MD5: bc90c938bc1170444a691cdc04ec733e
Detection count: 7,872
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local
Group: Malware file
Last Updated: October 26, 2018
file.exe
File name: file.exeSize: 55.3 KB (55300 bytes)
MD5: b2e826c55a437e528d846b90d5aa743b
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: June 20, 2012
file.exe
File name: file.exeSize: 34.8 KB (34808 bytes)
MD5: 40a5dd7fd8a1d9a2027070db784440f7
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: June 20, 2012
file.exe
File name: file.exeSize: 602.62 KB (602624 bytes)
MD5: f7d45793226820996c9b3642f644bebb
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: June 18, 2017
%ALLUSERSPROFILE%\mszjeb.exe
File name: mszjeb.exeSize: 172.03 KB (172032 bytes)
MD5: 0e9c6292025426164fc32f2413a84846
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: June 26, 2017
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.