Trojan

MemScan:Trojan.Small.M (file analysis)

Malware Removal

The MemScan:Trojan.Small.M is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Trojan.Small.M virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

bins.lop.com
ww6.lop.com

How to determine MemScan:Trojan.Small.M?


File Info:

crc32: 690D9AF9
md5: 579c15542b296450e13390127f554459
name: edonkey-gamer.exe
sha1: e6339e9ec507c0cafd81eda7bb9275036b8824b8
sha256: 61823c3b13453aae92614c1f7071aae059da02adffb32dcb930087ad5a4151b1
sha512: 4a92e056c0d5bd211bc6f85e1c743380990162ab1fcd371a16f711b3ec338d810ce94a63850e27bbe17618e641c6cbad49c497c763ed4f9caa9bd7ea04b483a3
ssdeep: 6144:KjsaQ7mWsG9je3nq2kKY+ALFhYMjhbhdaKaL5vxQ65Gmt2NqmZSXv+58tgcsA8W:usH6W23qP+WFhYMtqKuZJF8qNG58t92W
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

MemScan:Trojan.Small.M also known as:

MicroWorld-eScanMemScan:Trojan.Small.M
FireEyeMemScan:Trojan.Small.M
CAT-QuickHealTrojandownloader.Udepo
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanDownloader:Win32/Swizzor.df1adc62
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.42b296
ArcabitTrojan.Small.M
AvastWin32:Malware-gen
KasperskyTrojan-Downloader.Win32.Swizzor.i
BitDefenderMemScan:Trojan.Small.M
Paloaltogeneric.ml
AegisLabTrojan.Win32.Swizzor.a!c
RisingDownloader.Swizzor!8.749 (CLOUD)
SophosMal/Generic-S
F-SecureTrojan.TR/Dldr.Swizzor.kofsf
DrWebTrojan.ViriSign.10176
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DE920
McAfee-GW-EditionRDN/Generic Downloader.x
MaxSecureTrojan.Malware.1846175.susgen
CMCTrojan.Win32.Cosmu!O
EmsisoftMemScan:Trojan.Small.M (B)
CyrenW32/Downloader.JBED-8563
JiangminTrojan/Foreign.snt
AviraTR/Dldr.Swizzor.kofsf
FortinetW32/Swizzor.I!tr.dldr
MicrosoftTrojanDownloader:Win32/Udepo
ViRobotTrojan.Win32.Z.Small.431513
ZoneAlarmTrojan-Downloader.Win32.Swizzor.i
ALYacMemScan:Trojan.Small.M
MAXmalware (ai score=81)
Ad-AwareMemScan:Trojan.Small.M
ESET-NOD32a variant of Generik.ZUZWE
TrendMicro-HouseCallTROJ_GEN.R002C0DE920
TencentWin32.Trojan-downloader.Swizzor.Swvc
IkarusTrojan.SuspectCRC
GDataMemScan:Trojan.Small.M
AVGWin32:Malware-gen
PandaTrj/CI.A
Qihoo-360Win32/Trojan.Downloader.dd4

How to remove MemScan:Trojan.Small.M?

MemScan:Trojan.Small.M removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment