Ransom Trojan

Trojan-Ransom.Win32.Foreign.msai malicious file

Malware Removal

The Trojan-Ransom.Win32.Foreign.msai is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Foreign.msai virus can do?

  • Executable code extraction
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Danish
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.Foreign.msai?


File Info:

crc32: 17C4537A
md5: adf6fc0c07d0d26c3a781b67843706fe
name: ADF6FC0C07D0D26C3A781B67843706FE.mlw
sha1: 09ec7321bf13b10117247dbd8e339a04ead44ba9
sha256: d3319fefd1ed975b2f1d18d5b5332dcaa8e1e597b606c9cac85f98af6ca6dc13
sha512: fc926324bc572e378108727aadcb80b19fa503d7224cb3c8d644550cd0fb8839bbd0a00c4d52e476c4461815467db52349a5e51ecf10277b93d3a5120c1b217d
ssdeep: 6144:72YWzFU7bl6xGbS0AzdMDECF/qb19G3eo:7vWzFzi74Cq19Sh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0406 0x04b0
LegalCopyright: Utter Miint
InternalName: Felsmalerei
FileVersion: 1.00
CompanyName: PreSonus
LegalTrademarks: Utter Miint
ProductName: Utter Miint
ProductVersion: 1.00
FileDescription: Utter Miint
OriginalFilename: Felsmalerei.exe

Trojan-Ransom.Win32.Foreign.msai also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0056faf91 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.32796
CynetMalicious (score: 100)
CAT-QuickHealTrojan.VBObfuscator.GN3
McAfeePWSZbot-FAHE!ADF6FC0C07D0
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.53547
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0056faf91 )
Cybereasonmalicious.c07d0d
NANO-AntivirusTrojan.Win32.RiskGen.dxjwiz
ESET-NOD32Win32/Spy.Zbot.ABV
ZonerTrojan.Win32.35105
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Foreign.msai
BitDefenderGen:Heur.PonyStealer.tm0@eKxFnybG
ViRobotTrojan.Win32.Ransom.315392.L
SUPERAntiSpywareTrojan.Agent/Gen-VB
MicroWorld-eScanGen:Heur.PonyStealer.tm0@eKxFnybG
TencentMalware.Win32.Gencirc.114c9065
Ad-AwareGen:Heur.PonyStealer.tm0@eKxFnybG
SophosML/PE-A + Troj/Zbot-KAL
BitDefenderThetaGen:NN.ZevbaF.34758.tm0@aKxFnybG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Fareit.fc
FireEyeGeneric.mg.adf6fc0c07d0d26c
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Foreign.abnd
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1119911
ArcabitTrojan.PonyStealer.ED12056
ZoneAlarmTrojan-Ransom.Win32.Foreign.msai
GDataGen:Heur.PonyStealer.tm0@eKxFnybG
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
VBA32TScope.Trojan.VB
MAXmalware (ai score=80)
RisingTrojan.Win32.Foreign.ao (CLASSIC)
YandexTrojan.Foreign!zLWP9vKDwAc
FortinetW32/Injector.CHFH!tr
AVGWin32:Malware-gen

How to remove Trojan-Ransom.Win32.Foreign.msai?

Trojan-Ransom.Win32.Foreign.msai removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment