Ransom

Should I remove “Ransom.NMoreira”?

Malware Removal

The Ransom.NMoreira is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.NMoreira virus can do?

  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Installs itself for autorun at Windows startup
  • Clears Windows events or logs
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom.NMoreira?


File Info:

crc32: 9F2DEB69
md5: afa2e8e1d6a11f914d347c857370eaf9
name: AFA2E8E1D6A11F914D347C857370EAF9.mlw
sha1: 54cf97ce6fa627523a907309a05f9b1009a033f3
sha256: 4eaee75960ed4c7d8ed329bf7ff52fb7a80a0aa37f0b6ade6c6b961ace783786
sha512: 480b1b9cbd17f21a8e482687def612fc4c70166ef79c5ede48d10c5616e3407dc3ec632c822618d13b58ae9f6fa84f1a0fd4a048111064c31c4c3725997c1349
ssdeep: 24576:6PlI0vZYBxyG942+6ytOnvekeTIgG2qqRn/qCC8As5VrJ6I/CC8As5VrJ6I:7yOveTIsqqRUdszrJ6IHdszrJ6I
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Ransom.NMoreira also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.EmotetU.Gen.QLW@h8RQsbp
FireEyeGeneric.mg.afa2e8e1d6a11f91
McAfeeGenericRXAY-JJ!AFA2E8E1D6A1
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforVirus_Suspicious.Win32.Sality.ae
K7AntiVirusTrojan ( 0050109d1 )
BitDefenderTrojan.EmotetU.Gen.QLW@h8RQsbp
K7GWTrojan ( 0050109d1 )
Cybereasonmalicious.1d6a11
BitDefenderThetaGen:NN.ZexaF.34590.QLW@a8RQsbp
CyrenW32/Ransom.CS.gen!Eldorado
SymantecRansom.Haknata!g1
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Ransomware.Razy-7547555-0
KasperskyTrojan-Ransom.Win32.Xpan.c
AlibabaRansom:Win32/Haknata.ca5ba363
NANO-AntivirusTrojan.Win32.Deshacop.ejnnls
AegisLabTrojan.Win32.Xpan.tnLc
TencentMalware.Win32.Gencirc.10b54b49
Ad-AwareTrojan.EmotetU.Gen.QLW@h8RQsbp
SophosMal/Generic-S
ComodoTrojWare.Win32.Ransom.XRatLocker.D@7b6770
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Encoder.10157
ZillyaTrojan.Deshacop.Win32.755
TrendMicroMal_Hakuna-1
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
EmsisoftTrojan.EmotetU.Gen.QLW@h8RQsbp (B)
JiangminTrojan.Deshacop.tf
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Deshacop
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.EmotetU.Gen.EDFE40
ZoneAlarmTrojan-Ransom.Win32.Xpan.c
GDataWin32.Trojan-Ransom.XPan.B
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Ransom.R194613
ALYacTrojan.EmotetU.Gen.QLW@h8RQsbp
MAXmalware (ai score=83)
VBA32TrojanRansom.Xpan
MalwarebytesRansom.NMoreira
ESET-NOD32a variant of Win32/Filecoder.XRatLocker.D
TrendMicro-HouseCallMal_Hakuna-1
RisingRansom.Haknata!8.E480 (TFE:5:c806rtvHGk)
YandexTrojan.GenAsa!Xt2ppgIjJzg
SentinelOneStatic AI – Malicious PE
FortinetW32/Generic.AC.3B17B2!tr
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Ransom.Generic.HxQB93AA

How to remove Ransom.NMoreira?

Ransom.NMoreira removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment