Spy Trojan

Should I remove “Trojan-Spy.Win32.AveMaria.dyh”?

Malware Removal

The Trojan-Spy.Win32.AveMaria.dyh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.AveMaria.dyh virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location

How to determine Trojan-Spy.Win32.AveMaria.dyh?


File Info:

name: 8B428C1A4AA149770B7A.mlw
path: /opt/CAPEv2/storage/binaries/94cdb8c1e45579d7f06f4aa7999e179b09e6a29404e44722c33ba200e2c70d65
crc32: 892EE350
md5: 8b428c1a4aa149770b7a6496950a4957
sha1: 855fcd9b02d64297e46f83b76e57394762fe49a5
sha256: 94cdb8c1e45579d7f06f4aa7999e179b09e6a29404e44722c33ba200e2c70d65
sha512: eab5431af84a3372f0ffc0cd21ef2e15fc71e32169736d18e31799702bd6e5e7ac521e235e9028dc4a7bace525b422320db73295297a42c960ff97be30d9fe76
ssdeep: 98304:qbLxaDFIReDk2vRUvOVhW8AF9qIfDpqj27KhWGxVNaejTZmBIxn0t63Oj5w:qXxaDySjhW//tqjtJ/NaejTZmBDZm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17C5633A0B9D045F2DE7538F15D16B9B004FA6C241260876F67F076A99AB24C3DE36B0F
sha3_384: e153a3b1f54bb78e9138dcbff926bda79b35afe2b8c15b9279bb8e63720c281dbf209120e5b410e2c3415257dde0299b
ep_bytes: e874040000e988feffff3b0d68e64300
timestamp: 2020-12-01 18:00:55

Version Info:

0: [No Data]

Trojan-Spy.Win32.AveMaria.dyh also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
FireEyeGeneric.mg.8b428c1a4aa14977
SangforSuspicious.Win32.Save.a
K7GWTrojan ( 00563a1b1 )
K7AntiVirusTrojan ( 00563a1b1 )
BitDefenderThetaGen:NN.ZexaF.34182.@NW@ayvxzQf
ESET-NOD32multiple detections
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.AveMaria.dyh
BitDefenderTrojan.GenericKD.48209969
MicroWorld-eScanTrojan.GenericKD.48209969
AvastWin32:Evo-gen [Susp]
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
EmsisoftTrojan.GenericKD.48209969 (B)
IkarusTrojan.Win32.VMProtect
GDataWin32.Backdoor.Ghost.GNPU66
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.351D5A3
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win32.Generic.C4156681
VBA32TScope.Malware-Cryptor.SB
ALYacGen:Variant.MSILPerseus.199414
MalwarebytesTrojan.Dropper
TrendMicro-HouseCallTROJ_GEN.R002H07B122
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:384ufIdRqItBoxafkWEk8Q)
YandexTrojan.VMProtect!NXH/BdUW+q0
SentinelOneStatic AI – Malicious SFX
FortinetW32/PossibleThreat
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.a4aa14

How to remove Trojan-Spy.Win32.AveMaria.dyh?

Trojan-Spy.Win32.AveMaria.dyh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment