Ransom Trojan

What is “Trojan-Ransom.Win32.Foreign.npfm”?

Malware Removal

The Trojan-Ransom.Win32.Foreign.npfm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Foreign.npfm virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to disable Windows Defender
  • Attempts to modify or disable Security Center warnings

How to determine Trojan-Ransom.Win32.Foreign.npfm?


File Info:

crc32: E726795E
md5: 97a18870e8bde19f1f848c264c80367d
name: 97A18870E8BDE19F1F848C264C80367D.mlw
sha1: 4eb0b4d9725620670c82dab0cd2d5d5c911ebe31
sha256: 7f6ae1e6854f8831f7c9129a1d607fac3ebc2ae8c9c50c3ebea5ff396b2a5770
sha512: 67f491437a08c0751bb796e96b11b4d88746c130d1a3b2942ec2ecf65443df079e29ec61074c686d4459a45d354bab05beeb40ed47602e0a30180f3077476800
ssdeep: 3072:1PiA7/Fp49njM1t+yNpi9wv9zlQtCiUZEb2vSDactPaebliSa4gVmlCUU3:F3//ybyNpiczIbj+ctPaciB/ElHs
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C)Vojnic Ladislav
CompanyName: Vojnic Ladislav
LegalTrademarks: (C)Vojnic Ladislav
ProductName: Interim
ProductVersion: 4.6.7.1
FileDescription: Bool Xmltextreader Disagree Dear Week Portuguese
OriginalFilename: Interim.exe
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Foreign.npfm also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0051a67e1 )
Elasticmalicious (high confidence)
DrWebWin32.HLLM.Reset.480
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.56750
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Foreign.acffb474
K7GWTrojan ( 0051a67e1 )
Cybereasonmalicious.972562
SymantecW32.Ramnit!dr
ESET-NOD32Win32/Ramnit.BV
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Emotet-6363857-0
KasperskyTrojan-Ransom.Win32.Foreign.npfm
NANO-AntivirusTrojan.Win32.Reset.eusdgl
TencentWin32.Trojan.Inject.Auto
SophosMal/Generic-S
ComodoMalware@#2id7whnwbbul1
BitDefenderThetaGen:NN.ZexaF.34608.sq0@aud8M6oi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPLOCKY.SME
FireEyeGeneric.mg.97a18870e8bde19f
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Emotet
AviraHEUR/AGEN.1104894
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Tiggre!rfn
AegisLabTrojan.Win32.Generic.4!c
AhnLab-V3Win-Trojan/Sagecrypt.Gen
Acronissuspicious
McAfeeArtemis!97A18870E8BD
MAXmalware (ai score=100)
VBA32TrojanRansom.Foreign
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/CI.A
TrendMicro-HouseCallRansom_HPLOCKY.SME
RisingVirus.Ramnit!8.4 (CLOUD)
IkarusVirus.Win32.Ramnit
FortinetW32/Generic.SME!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Foreign.HgIASOUA

How to remove Trojan-Ransom.Win32.Foreign.npfm?

Trojan-Ransom.Win32.Foreign.npfm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment