Spy Trojan

TrojanSpy:Win32/AveMaria!MTB removal instruction

Malware Removal

The TrojanSpy:Win32/AveMaria!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/AveMaria!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Attempts to mimic the file extension of a PDF document by having ‘pdf’ in the file name.
  • A scripting utility was executed
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanSpy:Win32/AveMaria!MTB?


File Info:

crc32: FFA75EDA
md5: 48ad0ffe0b3209700f2b2d73cf2777dc
name: faktura_202003_3817449.pdf.exe
sha1: 3121376a415eec170669e98a30a7d473dda526db
sha256: fe974cd55e593d754c3dca74db62bc2fb48f9144c7098eedcf3b9abad1fe05e2
sha512: 33e0ccb20a747d12bbb3faf3a7d0a35c0e0afb34dc590f4fd7ec467a0acb8219914a2d564868764e663dcb1330cfb79a05fd083cf9b51ee85070a39afb5b6f84
ssdeep: 24576:xaWITosPn6QioFluorVvze6nnjqKoedG:xin6QCorpzDjqKoes
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanSpy:Win32/AveMaria!MTB also known as:

MicroWorld-eScanGen:Variant.Ulise.103537
FireEyeGeneric.mg.48ad0ffe0b320970
Qihoo-360Generic/HEUR/QVM20.1.470B.Malware.Gen
McAfeeGenericRXAA-AA!48AD0FFE0B32
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005636a21 )
BitDefenderGen:Variant.Ulise.103537
K7GWTrojan ( 005636a21 )
CrowdStrikewin/malicious_confidence_80% (W)
TrendMicroTROJ_GEN.R002C0DD120
ESET-NOD32a variant of Generik.ESJVTQZ
APEXMalicious
AvastWin32:Trojan-gen
GDataGen:Variant.Ulise.103537
AlibabaTrojan:Application/Generic.cf714953
AegisLabTrojan.Win32.Ulise.4!c
RisingMalware.Undefined!8.C (CLOUD)
Ad-AwareGen:Variant.Ulise.103537
EmsisoftGen:Variant.Ulise.103537 (B)
F-SecureTrojan.TR/AD.MortyStealer.dsenk
DrWebTrojan.PWS.Maria.3
ZillyaTrojan.AveMaria.Win32.455
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
SophosMal/Generic-S
IkarusTrojan.Agent
CyrenW32/Trojan.SNJC-2380
WebrootW32.Trojan.Gen
AviraTR/AD.MortyStealer.dsenk
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
ArcabitTrojan.Ulise.D19471
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojanSpy:Win32/AveMaria!MTB
VBA32Trojan.Wacatac
ALYacTrojan.PSW.AveMaria
MalwarebytesBackdoor.AveMaria
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DD120
TencentMalware.Win32.Gencirc.10b9a5a6
YandexTrojan.GenKryptik!
FortinetW32/Generik.ESJVTQZ!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove TrojanSpy:Win32/AveMaria!MTB?

TrojanSpy:Win32/AveMaria!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment