Ransom Trojan

Trojan-Ransom.Win32.Foreign.cmev malicious file

Malware Removal

The Trojan-Ransom.Win32.Foreign.cmev is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Foreign.cmev virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.Foreign.cmev?


File Info:

crc32: C3B1F84B
md5: 5dd73678a24d39031b6b6a62d3d16de0
name: 5DD73678A24D39031B6B6A62D3D16DE0.mlw
sha1: f932d2b0b9b82e06ee3e51fef9863ab4cd077b05
sha256: c49e4177190899c5f0507f738072c2a221e1fd0cd6f0823d2e4a136cd6beb55c
sha512: 2e303d404887ab73e3f97d0f4b46a9d743adb31f1ad296023c13aaa61596d502351bd6eb2c6f1dda04460ea59d3800e248ff0428495338c192057be9c66eee59
ssdeep: 1536:nXTNI7WyKQ+/+cyJHsZgoOkKQo4VauIGuh/RrP7+HDL:ZIIKcypsZDOkRo4Va/ZRj7+HDL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Foreign.cmev also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0040f3c81 )
DrWebTrojan.Winlock.8128
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Urausy.C
ALYacGen:Heur.VIZ.8
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.930346
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Foreign.91dfadd1
K7GWTrojan ( 0040f3c81 )
Cybereasonmalicious.8a24d3
CyrenW32/FakeAlert.WR.gen!Eldorado
ESET-NOD32Win32/LockScreen.APR
APEXMalicious
AvastWin32:Reveton-RX [Trj]
ClamAVWin.Ransomware.Generickdz-9652412-0
KasperskyTrojan-Ransom.Win32.Foreign.cmev
BitDefenderGen:Heur.VIZ.8
NANO-AntivirusTrojan.Win32.RiskGen.cqjtxq
ViRobotTrojan.Win32.Ransom.98304.E
SUPERAntiSpywareTrojan.Agent/Gen-FakeAV
MicroWorld-eScanGen:Heur.VIZ.8
TencentWin32.Trojan.Foreign.Tapj
Ad-AwareGen:Heur.VIZ.8
SophosML/PE-A + Mal/Ransom-AO
ComodoTrojWare.Win32.Kryptik.BAQC@4xm2qg
BitDefenderThetaGen:NN.ZexaF.34628.gqW@ay@Oe6ki
VIPRETrojan.Win32.FakeAV.ka (v)
McAfee-GW-EditionRansom-FBXU!5DD73678A24D
FireEyeGeneric.mg.5dd73678a24d3903
EmsisoftGen:Heur.VIZ.8 (B)
JiangminTrojan/Foreign.fju
WebrootW32.Rogue.Gen
AviraTR/Rogue.9830458
eGambitGeneric.Malware
KingsoftWin32.Troj.LockScreen.A.(kcloud)
MicrosoftVirTool:Win32/Obfuscator.AFQ
ArcabitTrojan.VIZ.8
AegisLabTrojan.Win32.Foreign.4!c
GDataGen:Heur.VIZ.8
AhnLab-V3Trojan/Win32.Foreign.R67643
Acronissuspicious
McAfeeRansom-FBXU!5DD73678A24D
MAXmalware (ai score=100)
VBA32BScope.Trojan.Agent
MalwarebytesTrojan.FakeAlert.RGenX
PandaTrj/Resdec.HEU
RisingTrojan.Kryptik!1.66AB (CLOUD)
YandexTrojan.GenAsa!Z8FPBd6tpW4
IkarusTrojan.Win32.FakeAV
FortinetW32/SystemSecurity.AL!tr
AVGWin32:Reveton-RX [Trj]
Qihoo-360Win32/Ransom.Urausy.HwgAEpsA

How to remove Trojan-Ransom.Win32.Foreign.cmev?

Trojan-Ransom.Win32.Foreign.cmev removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment