Trojan

What is “Trojan:Win32/AveMaria!MSR”?

Malware Removal

The Trojan:Win32/AveMaria!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/AveMaria!MSR virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/AveMaria!MSR?


File Info:

name: 444D3EBC1F3DDD74F5D7.mlw
path: /opt/CAPEv2/storage/binaries/55fc10ee991ca372843138e21109e0941cb42f5ae70f40a9442aed3bf98f2642
crc32: C6DBFC90
md5: 444d3ebc1f3ddd74f5d7a34cfec5a7f9
sha1: 4e2b96ddf559ced47e5f5033b3fcbf59f275551e
sha256: 55fc10ee991ca372843138e21109e0941cb42f5ae70f40a9442aed3bf98f2642
sha512: bafe4d7c103293fb30a4957bd41a564aa55f0ce334938ffa842063e96b236efeb6963182620f66730c492919a503b7dd948511dc2823a744dc3973e850c7f5aa
ssdeep: 12288:zI8s0DKNDSm75qjiYDJF7sjdCNBmPSXqEGuiqVGziafKehK0o:zU0uN2ywWYD3gjzK0o
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14EF44A9534C420EDD8E7D1F9CE51DC3B9A607C6A8202524AA1EF3C5BBA7DD53DE180B2
sha3_384: de67d2cb38607254fb241d169cd75623b0b9c00bba043027458ebeb577ab1326f09d8d842766a7504208bee447f76a5f
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-01-03 23:40:21

Version Info:

Translation: 0x0000 0x04b0
Comments: Computerized Employee Record by Aghawoha Joy
CompanyName: HAMPLUS TECH INT
FileDescription: Computerized Employee
FileVersion: 1.0.0.0
InternalName: TU0njoD.exe
LegalCopyright: Copyright © 2012
LegalTrademarks:
OriginalFilename: TU0njoD.exe
ProductName: Computerized Employee
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:Win32/AveMaria!MSR also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38441615
FireEyeGeneric.mg.444d3ebc1f3ddd74
CAT-QuickHealTrojan.IGENERIC
ALYacTrojan.PSW.AveMaria
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3667237
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c8b81 )
AlibabaTrojan:Win32/starter.ali1000139
K7GWTrojan ( 0058c8b81 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilF.34182.Tm0@a8rZXhe
CyrenW32/MSIL_Kryptik.DZG.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of MSIL/Kryptik.ADWS
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Taskun.gen
BitDefenderTrojan.GenericKD.38441615
AvastWin32:MalwareX-gen [Trj]
TencentMsil.Trojan.Taskun.Pavt
Ad-AwareTrojan.GenericKD.38441615
EmsisoftTrojan.Crypt (A)
ComodoMalware@#1tu9eu10tjbne
TrendMicroTROJ_FRS.0NA103A522
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
SophosMal/Generic-S
IkarusTrojan.MSIL.Krypt
GDataTrojan.GenericKD.38441615
AviraTR/AD.MortyStealer.spuhl
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.3500BDB
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/AveMaria!MSR
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4897382
McAfeeRDN/Generic.rp
TACHYONTrojan/W32.DN-Taskun.750592
MalwarebytesTrojan.Crypt.MSIL
TrendMicro-HouseCallTROJ_FRS.0NA103A522
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL:XON4rK4cTOY2ec/HitHquw)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.CYQ!tr
WebrootW32.Trojan.Gen
AVGWin32:MalwareX-gen [Trj]
PandaTrj/CI.A

How to remove Trojan:Win32/AveMaria!MSR?

Trojan:Win32/AveMaria!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment