Spy Trojan

About “Trojan-Spy.Win32.AveMaria.dcd” infection

Malware Removal

The Trojan-Spy.Win32.AveMaria.dcd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.AveMaria.dcd virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Code injection with CreateRemoteThread in a remote process
  • Attempts to remove evidence of file being downloaded from the Internet
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Spy.Win32.AveMaria.dcd?


File Info:

crc32: A7321145
md5: 52819b7d6743ce48630f57b2c6979f8c
name: putty.exe
sha1: 3180a8a1a50136daa7ac330ccee1a55d70360fcb
sha256: 4276e2e076e8b02efaf5f3f83be36f7d5dd36a345d6629436b592167199c7b08
sha512: a520dc770cd3af207813d2443ed2c454fb31d7198f84395e4d14fd3d4d0832bde9262432b91ae07a2a925d76e3be5bad39a3968c21aa9b0b4de6be1e87a1d8c0
ssdeep: 12288:husQt16jIVtp1IBmNcRucPi+wXvCxBWf45C2WM4CJ2lkgwDw:BQKsbfNDcPi+warm45C2gGa0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Spy.Win32.AveMaria.dcd also known as:

DrWebTrojan.PWS.Maria.4
MicroWorld-eScanTrojan.GenericKD.33781825
McAfeeGenericRXAA-AA!52819B7D6743
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0055def31 )
BitDefenderTrojan.GenericKD.33781825
K7GWTrojan ( 0055def31 )
BitDefenderThetaGen:NN.ZexaF.34108.UuW@aiMAWgli
F-ProtW32/Kryptik.BKJ.gen!Eldorado
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.33781825
KasperskyTrojan-Spy.Win32.AveMaria.dcd
AlibabaTrojanSpy:Win32/AveMaria.0a3a5826
AegisLabTrojan.Multi.Generic.4!c
TencentWin32.Trojan-spy.Avemaria.Sunp
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/AD.MortyStealer.usvpz
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.bh
MaxSecureTrojan.Malware.100850812.susgen
FireEyeGeneric.mg.52819b7d6743ce48
EmsisoftTrojan.GenericKD.33781825 (B)
IkarusTrojan.Inject
CyrenW32/Kryptik.BKJ.gen!Eldorado
WebrootW32.Trojan.Gen
AviraTR/AD.MortyStealer.usvpz
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftTrojan:Win32/Dynamer!rfn
ArcabitTrojan.Generic.D2037841
ZoneAlarmTrojan-Spy.Win32.AveMaria.dcd
AhnLab-V3Malware/Win32.Generic.C4088924
ALYacTrojan.GenericKD.33781825
MAXmalware (ai score=83)
VBA32TrojanPSW.Maria
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
ESET-NOD32Win32/Agent.TJS
TrendMicro-HouseCallTROJ_GEN.R002H0CE520
RisingTrojan.Kryptik!8.8 (CLOUD)
SentinelOneDFI – Suspicious PE
FortinetW32/Kryptik.GZUK!tr
Ad-AwareTrojan.GenericKD.33781825
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.Spy.fc3

How to remove Trojan-Spy.Win32.AveMaria.dcd?

Trojan-Spy.Win32.AveMaria.dcd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment