Trojan

How to remove “Trojan:Win32/AveMaria.NEBV!MTB”?

Malware Removal

The Trojan:Win32/AveMaria.NEBV!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/AveMaria.NEBV!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • A scripting utility was executed
  • CAPE detected the WarzoneRAT malware family
  • Attempts to modify Windows Defender using PowerShell
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Accesses or creates Warzone RAT directories and/or files
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/AveMaria.NEBV!MTB?


File Info:

name: 9EA108E031D29EE21B3F.mlw
path: /opt/CAPEv2/storage/binaries/650f8f70149f12df57e7f82a6ae2967ac198588ae0c0ac8291925337a3cc544a
crc32: 1F658A2A
md5: 9ea108e031d29ee21b3f81e503eca87d
sha1: 18efaefa801c24ca978fbbd22cf2645af5aeac1d
sha256: 650f8f70149f12df57e7f82a6ae2967ac198588ae0c0ac8291925337a3cc544a
sha512: 2dcf873f0f03b92f17866563f8f4f0406664f30acd3b01579036e5981b1bcf0e1b57736ff159e74a4901964ea7281b1a54b0cca1a7a27eec7cf66663b541ad4c
ssdeep: 12288:sL6TVNvxaMWDzvLpwBFygtmbCum1LJm3Toh6C0uhXAxjgH8n7XAW76XcpjvV6538:Q6TTvxaOygGdyQTQ6xx3Mjq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18ED50864E3901115E5A7A77F72A08BD0889E3C415C6EA78F1E470BD6CA2E2F4790C6F7
sha3_384: 91fe0c0d27b033d18728d52f0ed9e9f5ff36e38cb5ca8dc6897e1e149ba9e820fa60e562dcaaade0599bea9f7b945964
ep_bytes: e85b060000e923feffffc20000558bec
timestamp: 2022-10-23 18:37:06

Version Info:

CompanyName:
FileDescription: ComSpyCtl Module
FileVersion: 1, 0, 0, 1
InternalName: COMSPYCTL
LegalCopyright: Copyright 1997
OriginalFilename: COMSPYCTL.DLL
ProductName: ComSpyCtl Module
ProductVersion: 1, 0, 0, 1
Translation: 0x0409 0x04b0

Trojan:Win32/AveMaria.NEBV!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealer.12!c
MicroWorld-eScanGen:Variant.Zusy.440480
FireEyeGen:Variant.Zusy.440480
ALYacTrojan.PSW.AveMaria
MalwarebytesCrypt.Trojan.MSIL.DDS
ZillyaTrojan.Kryptik.Win32.3940636
K7AntiVirusTrojan ( 00599e471 )
AlibabaTrojanSpy:Win32/AveMaria.fef1233b
K7GWTrojan ( 00599e471 )
VirITTrojan.Win32.Genus.LZM
CyrenW32/ABRisk.EBGD-8678
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HQIW
APEXMalicious
ClamAVWin.Trojan.Emotet-9955184-0
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Zusy.440480
NANO-AntivirusTrojan.Win32.Stealer.jtftao
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10bd9ca4
SophosMal/Generic-S
F-SecureTrojan.TR/AD.MortyStealer.lvmqh
DrWebTrojan.Inject4.45875
VIPREGen:Variant.Zusy.440480
TrendMicroTROJ_GEN.R002C0DK322
McAfee-GW-EditionBehavesLike.Win32.Generic.vz
EmsisoftGen:Variant.Zusy.440480 (B)
IkarusTrojan.Win32.Crypt
GDataGen:Variant.Zusy.440480
JiangminTrojanSpy.Stealer.aehn
WebrootW32.Trojan.Emotet
GoogleDetected
AviraTR/AD.MortyStealer.lvmqh
Antiy-AVLTrojan/Win32.Kasablanka
ArcabitTrojan.Zusy.D6B8A0
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
MicrosoftTrojan:Win32/AveMaria.NEBV!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5287083
McAfeeGenericRXAA-AA!9EA108E031D2
MAXmalware (ai score=87)
VBA32TrojanSpy.AveMaria
Cylanceunsafe
PandaTrj/Chgt.AA
ZonerTrojan.Win32.149794
TrendMicro-HouseCallTROJ_GEN.R002C0DK322
RisingStealer.Agent!8.C2 (TFE:5:pRLkw6UN3EG)
MaxSecureTrojan.Malware.73793603.susgen
FortinetW32/Kryptik.HQIW!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/AveMaria.NEBV!MTB?

Trojan:Win32/AveMaria.NEBV!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment