Ransom Trojan

Trojan-Ransom.Win32.Foreign.nmac removal guide

Malware Removal

The Trojan-Ransom.Win32.Foreign.nmac is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Foreign.nmac virus can do?

  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs

How to determine Trojan-Ransom.Win32.Foreign.nmac?


File Info:

crc32: D60D44C8
md5: b3a76e0d0ae41ec0b6effb4795337709
name: B3A76E0D0AE41EC0B6EFFB4795337709.mlw
sha1: e6e4b60ea7ce1d9fe441e2b918a80bcd341d2aba
sha256: 046a99542fc91a59c0a253ad58bafc40d0533ae4cf1718c599e3c49e83758c06
sha512: 659c9ae07f768e0d27f070f5549664b25cfbde2f826eb8771b4329576e07c5678b2be1aa72770d340c4cabde6c2d66d297fe617dbdeca2908e1db3e7f5a1d0b6
ssdeep: 12288:/kYf6GryqPTQGmqtTOOHdSgo+Cy2IFnuC:smb7QQhO2dK+J2f
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: All rights reserved. iMobie Inc.
InternalName: Ad
FileVersion: 5.2.2.504
CompanyName: iMobie Inc.
PrivateBuild: 5.2.2.504
LegalTrademarks: All rights reserved. iMobie Inc.
Comments: Pcs Russell Meetings
ProductName: Ad
ProductVersion: 5.2.2.504
FileDescription: Pcs Russell Meetings
OriginalFilename: Ad.exe
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Foreign.nmac also known as:

BkavW32.AIDetect.malware2
K7AntiVirusSpyware ( 00505e681 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.44420397
CylanceUnsafe
ZillyaTrojan.Ursnif.Win32.850
SangforVirus.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWSpyware ( 00505e681 )
Cybereasonmalicious.d0ae41
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Ursnif.AO
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.Foreign.nmac
BitDefenderTrojan.GenericKD.44420397
NANO-AntivirusTrojan.Win32.Ursnif.enliwi
MicroWorld-eScanTrojan.GenericKD.44420397
TencentWin32.Trojan.Foreign.Pfjb
Ad-AwareTrojan.GenericKD.44420397
SophosML/PE-A + Troj/Gozi-GM
ComodoMalware@#13qwnwsfw73th
BitDefenderThetaGen:NN.ZexaF.34170.Fu0@aKii59fi
VIPRETrojan.Win32.Generic!BT
TrendMicroPossible_HPGen-38
McAfee-GW-EditionBehavesLike.Win32.Dropper.gc
FireEyeGeneric.mg.b3a76e0d0ae41ec0
EmsisoftTrojan.GenericKD.44420397 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1138861
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.1F47226
MicrosoftTrojan:Win32/Skeeyah.A!rfn
GDataTrojan.GenericKD.44420397
TACHYONRansom/W32.Foreign.508416.B
McAfeeArtemis!B3A76E0D0AE4
MAXmalware (ai score=100)
VBA32BScope.Trojan.Dimnie
PandaTrj/CI.A
TrendMicro-HouseCallPossible_HPGen-38
RisingTrojan.Generic@ML.99 (RDML:9eIjWUy5slfkDISKB6m2hA)
YandexTrojan.Foreign!jFKQizDUYq8
IkarusTrojan-Ransom.GandCrab
FortinetW32/Foreign.AO!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Foreign.nmac?

Trojan-Ransom.Win32.Foreign.nmac removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment