Trojan

Trojan.Foreign.Gen.3 (B) removal guide

Malware Removal

The Trojan.Foreign.Gen.3 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Foreign.Gen.3 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Indonesian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Mimics the file times of a Windows system file
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Foreign.Gen.3 (B)?


File Info:

crc32: 313E69DD
md5: 2a61ad10ef8d27219e61487a9d3ad784
name: 2A61AD10EF8D27219E61487A9D3AD784.mlw
sha1: 7df3a687c5c4f4dc373515bc30d290d7bc2589c0
sha256: cdf62c1b6ea7653e73bce7ad8bf6fb7a8de6ba27be5c71e50126c48c57085d6e
sha512: 833ceca57b91fbd8e996bb53c0e81e165faf59d005900c769c13eb43a76db1c5c707718593ce75efbc6d9b36f5eb0f25734495f302c677ebc774d65e2bd64931
ssdeep: 1536:3h507OPdMD5EyW98ACAtykKyTyYO6ehP1RSEZjCAdh1:UEs5Ey08ACAQkgqw1PuA9
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB) system file, for MS Windows

Version Info:

0: [No Data]

Trojan.Foreign.Gen.3 (B) also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Crypmod.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.145
CynetMalicious (score: 100)
ALYacTrojan.Foreign.Gen.3
CylanceUnsafe
ZillyaTrojan.Crypmod.Win32.8
AlibabaRansom:Win32/generic.ali2000010
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.0ef8d2
ESET-NOD32Win32/Gpcode.NAI
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
KasperskyTrojan-Ransom.Win32.Cryptor.bwl
BitDefenderTrojan.Foreign.Gen.3
NANO-AntivirusTrojan.Win32.Crypmod.dorikg
MicroWorld-eScanTrojan.Foreign.Gen.3
TencentWin32.Trojan.Crypmod.Hryv
Ad-AwareTrojan.Foreign.Gen.3
SophosMal/Generic-S
ComodoMalware@#3nqfgwlwchosb
BitDefenderThetaGen:NN.ZexaF.34126.gqW@aapELvmG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Emotet.cc
FireEyeGeneric.mg.2a61ad10ef8d2721
EmsisoftTrojan.Foreign.Gen.3 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Crypmod.l
WebrootW32.Malware.Gen
AviraTR/Crypt.ZPACK.122321
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASMalwS.E885A3
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Fortrypt.A
ArcabitTrojan.Foreign.Gen.3
ZoneAlarmTrojan-Ransom.Win32.Cryptor.bwl
GDataTrojan.Foreign.Gen.3
AhnLab-V3Trojan/Win32.ZBot.R135224
McAfeeGeneric-FAWE!2A61AD10EF8D
MAXmalware (ai score=100)
VBA32Hoax.Crypmod
PandaTrj/Genetic.gen
YandexTrojan.Crypmod!9FIy763Q4hk
IkarusTrojan-Downloader.Win32.Zurgop
MaxSecureTrojan.Malware.74693539.susgen
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml

How to remove Trojan.Foreign.Gen.3 (B)?

Trojan.Foreign.Gen.3 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment