Ransom Trojan

How to remove “Trojan-Ransom.Win32.Foreign.nmpc”?

Malware Removal

The Trojan-Ransom.Win32.Foreign.nmpc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Foreign.nmpc virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan-Ransom.Win32.Foreign.nmpc?


File Info:

name: A250340FFF0E1606A8BA.mlw
path: /opt/CAPEv2/storage/binaries/3eee2b58c6771ee47c07c2aa3ec96777413f0db3abc10cb5356b1bb98ca755be
crc32: 73663B68
md5: a250340fff0e1606a8ba28c689ff2053
sha1: ef20ddefc08bf9098e8707a524a57328b506493d
sha256: 3eee2b58c6771ee47c07c2aa3ec96777413f0db3abc10cb5356b1bb98ca755be
sha512: 8f16bbf0b1adbe373c7b5737c999812609999e0e6fcdb10104343fc5a172bc105f84a731b5b2437584ebce1f6fa92e278394a98fb1982d2cf842358f85c63ea1
ssdeep: 6144:tR6HzjOaHlFXBgnv169YcwDR66AGh9KkTF+tr0bUB8w7ZlDKb4rGb7:zEz/xg969+V6xGPzQRJ8O+b4rGb7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14C84F1C7F5A7D873FC080138855A85F4A736FC43B6628CCF1BA4BE4FE675284994122A
sha3_384: dfd1541fbb29b038a1221f428930bc1f259eaffb6ca9b5f20708cd861b7956be79b17344b94b0dcfb0c215c0b6722e4d
ep_bytes: e834630000e916feffff558bec81ec28
timestamp: 2017-05-02 02:33:46

Version Info:

OriginalFilename: 9cHandheld
FileDescription: Vercme Lags Biter
Comments: Vercme Lags Biter
LegalCopyright: Copyright ©MediaGet LLC. 1999 - 2014
ProductName: 9cHandheld
CompanyName: MediaGet LLC
LegalTrademarks: Copyright ©MediaGet LLC. 1999 - 2014
InternalName: 9cHandheld
PrivateBuild: 7.1.4.7
ProductVersion: 7.1.4.7
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Foreign.nmpc also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Foreign.j!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.4992010
FireEyeGeneric.mg.a250340fff0e1606
ALYacTrojan.GenericKD.4992010
MalwarebytesGeneric.Malware/Suspicious
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0047698f1 )
BitDefenderTrojan.GenericKD.4992010
K7GWTrojan ( 0047698f1 )
Cybereasonmalicious.fff0e1
ArcabitTrojan.Generic.D4C2C0A
BitDefenderThetaGen:NN.ZexaF.36196.yq0@a85!ZKli
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Delf.ATW
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Foreign.nmpc
AlibabaRansom:Win32/Foreign.9394b250
NANO-AntivirusTrojan.Win32.Stealer.eokbho
EmsisoftTrojan.GenericKD.4992010 (B)
F-SecureHeuristic.HEUR/AGEN.1312684
DrWebTrojan.PWS.Stealer.18284
VIPRETrojan.GenericKD.4992010
TrendMicroMal_HPGen-37b
McAfee-GW-EditionBehavesLike.Win32.Downloader.fc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Delf
WebrootW32.Trojan.GenKD
GoogleDetected
AviraHEUR/AGEN.1312684
Antiy-AVLTrojan/Win32.Delf
XcitiumMalware@#2c94abpcggafy
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ZoneAlarmTrojan-Ransom.Win32.Foreign.nmpc
GDataTrojan.GenericKD.4992010
CynetMalicious (score: 99)
AhnLab-V3Win-Trojan/Sagecrypt.Gen
McAfeeArtemis!A250340FFF0E
MAXmalware (ai score=86)
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Dimnie
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallMal_HPGen-37b
TencentMalware.Win32.Gencirc.10be2b6e
YandexTrojan.Foreign!JFJe2iRtXiE
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.10880658.susgen
FortinetW32/Delf.ATW!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Ransom.Win32.Foreign.nmpc?

Trojan-Ransom.Win32.Foreign.nmpc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment