Ransom Trojan

Should I remove “Trojan-Ransom.Win32.Foreign.nnym”?

Malware Removal

The Trojan-Ransom.Win32.Foreign.nnym is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Foreign.nnym virus can do?

  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.Foreign.nnym?


File Info:

crc32: 735DEB4B
md5: 850a24ba71e5352a7cc0640fb25b0d47
name: 850A24BA71E5352A7CC0640FB25B0D47.mlw
sha1: 24e4ec1e321223bf3878933c39ad46b76a5af4c3
sha256: 5867050d3ad2f2962278156c55edcba4c0881157fd6f6b92ba586becc731e1c8
sha512: 60e7c97f299aae4f37618fe6a643c9e6ed7453334d62f8fd74bad2b4a1b73466b8d7916771d22536f2f64790c3df641304ca094a1e81864c31a0c9e64e2ae22d
ssdeep: 12288:p0EFfZn/oK9h6TlCOM39cWi8N3It4Zg7FyFIsLPQ+2su3/cV+TFJSszQc:p0EJZB94QOMcEg7FyFI2PQLl/s+TJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (c) 1993-2015 NPC Geotec
InternalName: prime32.exe
FileVersion: 4.38.5.1
CompanyName: NPC Geotec
ProductName: prime32
ProductVersion: 4.38.502.4429
FileDescription: x41cx43ex434x443x43bx44c x433x440x430x444x438x447x435x441x43ax43ex433x43e x43cx43ex43dx438x442x43ex440x430 (release 20150831_01_stable rev.20522 built 2015-08-31 22:34:48 on SERVER)
OriginalFilename: prime32.exe
Translation: 0x0000 0x04b0

Trojan-Ransom.Win32.Foreign.nnym also known as:

ALYacTrojan.GenericKD.36892116
BitDefenderTrojan.GenericKD.36892116
KasperskyTrojan-Ransom.Win32.Foreign.nnym
AlibabaRansom:Win32/Foreign.cef141a4
MicroWorld-eScanTrojan.GenericKD.36892116
Ad-AwareTrojan.GenericKD.36892116
McAfee-GW-EditionBehavesLike.Win32.BadFile.dh
FireEyeTrojan.GenericKD.36892116
EmsisoftTrojan.GenericKD.36892116 (B)
ArcabitTrojan.Generic.D232EDD4
AegisLabTrojan.Win32.Foreign.j!c
GDataTrojan.GenericKD.36892116
McAfeeArtemis!850A24BA71E5
MAXmalware (ai score=80)
PandaTrj/CI.A

How to remove Trojan-Ransom.Win32.Foreign.nnym?

Trojan-Ransom.Win32.Foreign.nnym removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment