Ransom

Ransom:Win32/Aurora.SIB!MTB removal instruction

Malware Removal

The Ransom:Win32/Aurora.SIB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Aurora.SIB!MTB virus can do?

  • Steals private information from local Internet browsers
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs

How to determine Ransom:Win32/Aurora.SIB!MTB?


File Info:

crc32: 6FA63B6C
md5: 4b1111e3ff64fa9836047ed70f0e93b2
name: 4B1111E3FF64FA9836047ED70F0E93B2.mlw
sha1: 44013f5f6f5c88482441f1fa673e1ada7d6e845f
sha256: d1b6ee9b716fe48e51ac4e6bec691366bb08d507773d61a5d14fb15ec5e25e2b
sha512: 166e785132a0474149196cbd77f0b4644a3676dc8f4b7e55ece6e92275e1caffd30db2a82a0b3f3dd1ba52dd2683dfc74dfc5f669990d4157a9af17b6c0c793a
ssdeep: 12288:eMrjOFAQS+OeO+OeNhBBhhBBIIeVZkD09768Hv7tsRM57Q:eMrjCutVGD0564TGM5
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Aurora.SIB!MTB also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Encoder.33561
CynetMalicious (score: 100)
CAT-QuickHealRansom.Mespinoza.R7
ALYacGeneric.Ransom.Mespinoza.1D1FC790
CylanceUnsafe
Cybereasonmalicious.3ff64f
SymantecRansom.Gen
ESET-NOD32a variant of Win32/Filecoder.NYO
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Mespinoza-9819427-0
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderGeneric.Ransom.Mespinoza.1D1FC790
NANO-AntivirusTrojan.Win32.Encoder.ioekej
MicroWorld-eScanGeneric.Ransom.Mespinoza.1D1FC790
Ad-AwareGeneric.Ransom.Mespinoza.1D1FC790
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1140496
BitDefenderThetaGen:NN.ZexaF.34686.FCW@aOImIIoi
TrendMicroRansom.Win32.MESPINOZA.SMDA
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
FireEyeGeneric.Ransom.Mespinoza.1D1FC790
EmsisoftGeneric.Ransom.Mespinoza.1D1FC790 (B)
JiangminTrojan.Generic.guqez
AviraHEUR/AGEN.1140496
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Aurora.SIB!MTB
ArcabitGeneric.Ransom.Mespinoza.1D1FC790
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataGeneric.Ransom.Mespinoza.1D1FC790
AhnLab-V3Malware/Win32.Generic.C4289671
McAfeeRansom-Mespinoz!4B1111E3FF64
MAXmalware (ai score=87)
MalwarebytesRansom.Mespinoza
TrendMicro-HouseCallRansom.Win32.MESPINOZA.SMDA
RisingRansom.Agent!1.C222 (RDMK:cmRtazr3c4zt7EQjMzGu4qCNFlP3)
YandexTrojan.GenAsa!qoUkCes1Sac
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Filecoder.NYO!tr.ransom
AVGWin32:RansomX-gen [Ransom]

How to remove Ransom:Win32/Aurora.SIB!MTB?

Ransom:Win32/Aurora.SIB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment