Threat Database Trojans Trojan.AveMaria.GF

Trojan.AveMaria.GF

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 74
First Seen: September 13, 2021
Last Seen: December 27, 2025
OS(es) Affected: Windows

The detection of Trojan.AveMaria.GF on your system indicates a potential security threat that requires immediate attention. Trojans are a type of malware that can cause significant damage to your computer and compromise your personal data. In this report, we will provide you with an overview of the threat, its operating methods, symptoms of infection, and a step-by-step guide on how to remove it from your system.

What Is Trojan.AveMaria.GF?

Trojan.AveMaria.GF is a type of Trojan malware that can infect your computer through various means, such as downloading malicious software, opening infected email attachments, or visiting compromised websites. Once installed, it can give unauthorized access to your system, allowing hackers to steal sensitive information, install additional malware, or use your computer for malicious activities.

How Trojan.AveMaria.GF Operates

Trojan.AveMaria.GF operates by exploiting vulnerabilities in your system's security, allowing it to gain access to your computer without your knowledge or consent. It can then communicate with its command and control servers to receive instructions and transmit stolen data. The malware may also attempt to disable your security software or hide its presence from detection.

Trojans like Trojan.AveMaria.GF can be particularly dangerous because they can be used to install additional malware, such as keyloggers, ransomware, or spyware, which can further compromise your system and steal your personal data. It is essential to remove the malware as soon as possible to prevent any further damage.

Symptoms of Infection

The symptoms of a Trojan.AveMaria.GF infection can vary, but common signs include slow system performance, frequent crashes, and unexpected pop-ups or advertisements. You may also notice that your browser is being redirected to unfamiliar websites or that your security software is disabled. In some cases, you may not notice any symptoms at all, which is why regular malware scans are crucial for detecting and removing threats like Trojan.AveMaria.GF.

  • Slow system performance
  • Frequent crashes or freezes
  • Unexpected pop-ups or advertisements
  • Browser redirection to unfamiliar websites
  • Disabled security software

How to Remove Trojan.AveMaria.GF

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove Trojan.AveMaria.GF and any other malware that may be present.
  3. Uninstall any suspicious programs that may be related to the malware infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.AveMaria.GF from your system requires careful attention to detail and a thorough understanding of the malware's operating methods. By following the steps outlined in this report, you can help to ensure that your system is free from the threat and that your personal data is protected. Remember to always be cautious when downloading software or opening email attachments, and to regularly scan your system for malware to prevent future infections.

Analysis Report

General information

Family Name: Trojan.AveMaria.GF
Signature status: No Signature

Known Samples

MD5: 2000c2eb3c53f635e67c9fbec52aaab2
SHA1: 9569317d710c56ae2be1526b24445dc42a4a1961
SHA256: 99F630F172A432AC73802F8A513CEE5926A89E98D2B1A04DF31FF4D48DAC6518
File Size: 954.37 KB, 954368 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Vimicro Corporation
File Description Capture Application (Sample)
File Version 3.1.000.4
Legal Copyright Copyright (C) 1999-2004 Vimicro Corporation
O L E Self Register AM20
Product Version 3.1.000.4

File Traits

  • x86

Block Information

Total Blocks: 3,349
Potentially Malicious Blocks: 36
Whitelisted Blocks: 3,078
Unknown Blocks: 235

Visual Map

0 0 0 ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? 0 ? ? ? ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 ? ? ? ? 0 ? 0 ? ? 0 ? ? ? ? ? ? ? ? 0 ? 0 ? 0 0 ? ? ? ? ? ? 0 ? ? 0 ? ? 0 ? ? ? 0 ? 0 ? ? ? ? ? ? 0 ? ? 0 ? ? ? 0 ? 0 ? ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 x 0 0 0 0 ? 0 ? 0 0 0 0 0 0 x 0 ? 0 x 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? 0 0 0 0 ? ? 0 0 x 0 x 0 0 0 0 0 0 0 x 0 0 ? ? 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? 0 0 ? ? 0 ? ? ? ? ? ? ? 0 ? 0 0 ? 0 0 ? 0 0 0 0 ? 0 0 ? ? ? ? 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 x x x x x 0 x x 0 0 0 0 0 0 0 x 0 x x x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 ? ? 0 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? 0 ? 0 ? 0 ? 0 0 1 0 ? ? 0 ? ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 ? ? ? 0 0 ? 0 0 ? ? 0 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 1 1 1 1 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\debug\9569317d710c56ae2be1526b24445dc42a4a1961_0000954368::logtofile RegNtPreCreateKey
HKLM\software\wow6432node\debug\9569317d710c56ae2be1526b24445dc42a4a1961_0000954368::timing RegNtPreCreateKey
HKLM\software\wow6432node\debug\9569317d710c56ae2be1526b24445dc42a4a1961_0000954368::trace RegNtPreCreateKey
HKLM\software\wow6432node\debug\9569317d710c56ae2be1526b24445dc42a4a1961_0000954368::memory RegNtPreCreateKey
HKLM\software\wow6432node\debug\9569317d710c56ae2be1526b24445dc42a4a1961_0000954368::locking RegNtPreCreateKey
HKLM\software\wow6432node\debug\9569317d710c56ae2be1526b24445dc42a4a1961_0000954368::error RegNtPreCreateKey
HKLM\software\wow6432node\debug\9569317d710c56ae2be1526b24445dc42a4a1961_0000954368::custom1 RegNtPreCreateKey
HKLM\software\wow6432node\debug\9569317d710c56ae2be1526b24445dc42a4a1961_0000954368::custom2 RegNtPreCreateKey
HKLM\software\wow6432node\debug\9569317d710c56ae2be1526b24445dc42a4a1961_0000954368::custom3 RegNtPreCreateKey
HKLM\software\wow6432node\debug\9569317d710c56ae2be1526b24445dc42a4a1961_0000954368::custom4 RegNtPreCreateKey
Show More
HKLM\software\wow6432node\debug\9569317d710c56ae2be1526b24445dc42a4a1961_0000954368::custom5 RegNtPreCreateKey
HKLM\software\wow6432node\debug\9569317d710c56ae2be1526b24445dc42a4a1961_0000954368::timeout ￿￿ RegNtPreCreateKey
HKLM\software\wow6432node\debug\global::timing RegNtPreCreateKey
HKLM\software\wow6432node\debug\global::trace RegNtPreCreateKey
HKLM\software\wow6432node\debug\global::memory RegNtPreCreateKey
HKLM\software\wow6432node\debug\global::locking RegNtPreCreateKey
HKLM\software\wow6432node\debug\global::error RegNtPreCreateKey
HKLM\software\wow6432node\debug\global::custom1 RegNtPreCreateKey
HKLM\software\wow6432node\debug\global::custom2 RegNtPreCreateKey
HKLM\software\wow6432node\debug\global::custom3 RegNtPreCreateKey
HKLM\software\wow6432node\debug\global::custom4 RegNtPreCreateKey
HKLM\software\wow6432node\debug\global::custom5 RegNtPreCreateKey
HKLM\software\wow6432node\debug\global::timeout ￿￿ RegNtPreCreateKey

Trending

Most Viewed

Loading...