Ransom Trojan

About “MemScan:Trojan.Ransom.AIG (B)” infection

Malware Removal

The MemScan:Trojan.Ransom.AIG (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Trojan.Ransom.AIG (B) virus can do?

  • Reads data out of its own binary image
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine MemScan:Trojan.Ransom.AIG (B)?


File Info:

crc32: E2BA2893
md5: 52d35ba0e2618691db59ac8799d4a25d
name: 52D35BA0E2618691DB59AC8799D4A25D.mlw
sha1: 1935c5c8292b6503a4987de294a5966e560594b2
sha256: 016b130bfd1223a9b31c543f33b9afa64a542f79d83bc38b853a00a5cf56c2dc
sha512: 1f170fd1cbfcf9b87783e69bf2e07e31197e8d04910a4aca2ef577b0ca65ac987cc4971f284c7ad2a211b29b8c8ed1d38726c3f5a7feb5e62d22716b233a9586
ssdeep: 3072:RwxVMhOC/dTDbq91+mno3t4QZQ3rpFxjzAdLVbFq+BMCnPabC8R8Q/:RTfFDbRnOTrpLAVMCibR1/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

MemScan:Trojan.Ransom.AIG (B) also known as:

K7AntiVirusTrojan ( 00405dcf1 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.Encoder.94
CynetMalicious (score: 99)
ALYacMemScan:Trojan.Ransom.AIG
ZillyaTrojan.Xorist.Win32.1639
K7GWTrojan ( 00405dcf1 )
Cybereasonmalicious.0e2618
CyrenW32/Filecoder.Y.gen!Eldorado
SymantecTrojan.Gen
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Filecoder-M [Trj]
KasperskyTrojan-Ransom.Win32.Xorist.er
BitDefenderMemScan:Trojan.Ransom.AIG
NANO-AntivirusTrojan.Win32.Xorist.dxuuhl
MicroWorld-eScanMemScan:Trojan.Ransom.AIG
TencentWin32.Trojan.Xorist.Swkx
SophosMal/EncPk-EY
ComodoPacked.Win32.MPEC.Gen@2oey7k
BitDefenderThetaGen:NN.ZexaF.34110.amW@aOn55Dn
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRansom-FASZ!874611FFD3A2
FireEyeMemScan:Trojan.Ransom.AIG
EmsisoftMemScan:Trojan.Ransom.AIG (B)
SentinelOneStatic AI – Malicious SFX
WebrootW32.Ransom.Gen
AviraTR/Crypt.PEPM.Gen
Antiy-AVLTrojan/Generic.ASCommon.3B
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftRansom:Win32/Sorikrypt.A
ArcabitTrojan.Ransom.AIG
ZoneAlarmHEUR:Trojan.Win32.KillFiles
GDataMemScan:Trojan.Ransom.AIG
McAfeeArtemis!52D35BA0E261
MAXmalware (ai score=87)
VBA32BScope.Backdoor.ProRat
PandaTrj/CI.A
RisingRansom.Xorist!1.CF6A (CLASSIC:Ue2ttyjCMDpZO3FTpUGtQQ)
YandexTrojan.Xorist!r0EGiJZptFY
IkarusTrojan.Win32.Filecoder
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Xorist.ER!tr
AVGWin32:Filecoder-M [Trj]
Paloaltogeneric.ml

How to remove MemScan:Trojan.Ransom.AIG (B)?

MemScan:Trojan.Ransom.AIG (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment