Trojan

Trojan:Win32/Amadey.AMY!MTB information

Malware Removal

The Trojan:Win32/Amadey.AMY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Amadey.AMY!MTB virus can do?

  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings
  • Appears to use command line obfuscation
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/Amadey.AMY!MTB?


File Info:

name: 12C54C614434BBD6C148.mlw
path: /opt/CAPEv2/storage/binaries/5debbe0aabb09c0e7072b2ef95e794d27fac081faeaad6cdad9c7cff4025f9af
crc32: F7845095
md5: 12c54c614434bbd6c148691ba2d87185
sha1: 9747a2f7a681ca36c46c1810eb203daaf25d32a0
sha256: 5debbe0aabb09c0e7072b2ef95e794d27fac081faeaad6cdad9c7cff4025f9af
sha512: 54a43ccd9e53bcba12ca3d90f675c7e51b9261eb75fbd5a362fbc13d820854840c1bad5596809f64691e65174921349c9e37143410aa0c3fba0843bb2758718d
ssdeep: 3072:K9y+bnr+O1I5GWp1icKAArDZz4N9GhbkrNEk19cobU3btQutRCIuN75Xo4A+e8oD:K9y+bnr+7p0yN90QE3biPXo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AE34D013E7DD8072D8B5177058F703C31B36BCA1AD78866B2795A85E0CB3694A93273B
sha3_384: 1fb541df3a42745376f906aa17a711a8b8ffa4cd651ca0d91d02855171b72f0d3795ea1f112f219e235651a5674c0aa3
ep_bytes: e8f0060000e9000000006a5868b87240
timestamp: 2022-05-24 22:49:06

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Win32 Cabinet Self-Extractor
FileVersion: 11.00.17763.1 (WinBuild.160101.0800)
InternalName: Wextract
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.17763.1
Translation: 0x0409 0x04b0

Trojan:Win32/Amadey.AMY!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Deyma.4!c
MicroWorld-eScanGen:Heur.Crifi.1
ClamAVWin.Malware.Doina-10001799-0
FireEyeGen:Heur.Crifi.1
CAT-QuickHealTrojan.GenericPMF.S30511625
ALYacGen:Heur.Crifi.1
Cylanceunsafe
ZillyaDownloader.Deyma.Win32.9047
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 005790d31 )
AlibabaTrojanDownloader:Win32/Deyma.e51adb3b
K7GWTrojan-Downloader ( 005790d31 )
Cybereasonmalicious.7a681c
VirITTrojan.Win32.Genus.RXJ
CyrenW32/Kryptik.JKR.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
CynetMalicious (score: 99)
KasperskyUDS:Trojan-Downloader.Win32.Deyma.gen
BitDefenderGen:Heur.Crifi.1
NANO-AntivirusTrojan.Win32.Deyma.jxeery
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:BotX-gen [Trj]
TencentMsil.Trojan.Agent.Iajl
EmsisoftGen:Heur.Crifi.1 (B)
F-SecureTrojan.TR/AD.Nekark.sgdjp
DrWebTrojan.Siggen21.5885
VIPREGen:Heur.Crifi.1
TrendMicroTrojan.Win32.AMADEY.YXDGGZ
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosTroj/PlugX-EC
IkarusTrojan.Win32.Amadey
GDataWin32.Trojan-Downloader.Amadey.D
JiangminTrojan.MSIL.aocbf
AviraTR/AD.Nekark.sgdjp
Antiy-AVLTrojan/Script.Phonzy
XcitiumApplicUnwnt@#1ftfc2ja2g1dd
ZoneAlarmHEUR:Trojan-Downloader.Win32.Deyma.gen
MicrosoftTrojan:Win32/Amadey.AMY!MTB
GoogleDetected
AhnLab-V3Trojan/Win.AntiAnalysis.R592037
Acronissuspicious
McAfeeTrojan-FVOI!12C54C614434
MAXmalware (ai score=80)
MalwarebytesMalware.AI.1727489235
PandaTrj/Chgt.AD
TrendMicro-HouseCallTrojan.Win32.AMADEY.YXDGGZ
RisingTrojan.Disabler!8.B58 (CLOUD)
YandexTrojan.DL.Amadey!3Y8Ogbnb+d8
SentinelOneStatic AI – Malicious SFX
FortinetW32/Amadey.A!tr
AVGWin32:BotX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Amadey.AMY!MTB?

Trojan:Win32/Amadey.AMY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment