Ransom Trojan

Should I remove “Trojan-Ransom.Win32.Foreign.nrbr”?

Malware Removal

The Trojan-Ransom.Win32.Foreign.nrbr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Foreign.nrbr virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Mimics the file times of a Windows system file
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Ransom.Win32.Foreign.nrbr?


File Info:

crc32: 7C3B5D39
md5: a44d8d3bda38076a6c84a1e45dfe0fa1
name: A44D8D3BDA38076A6C84A1E45DFE0FA1.mlw
sha1: f8e458577aad91eb5e85d101ee616b99e96a75ae
sha256: 7442586c6d6b5203b81e646d822e4e6535e8eede20841c268bb507e0f5f88f7f
sha512: 67273f36e5d9d84e7cbf6ab890085ab49b23b3d6c07708bd88307e0cd59ad28ae35fdf74d8cb70dfe5972c9f326ce6cca3d510a2967832e1aa980e4809ca9d41
ssdeep: 12288:aUERAlfdEPI8rJn+GWAf4ekKL18FXAp/t1SPL0PDcIlUkQ:aUERABdz8UGf4BKZNt8PI3Uv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: MP3jam
InternalName: mp3jamapp.Downloader.UI.exe
FileVersion: 1.1.1.11
CompanyName: MP3jam
LegalTrademarks: MP3jam
Comments: MP3jam
ProductName: MP3jam
ProductVersion: 1.1.1.11
FileDescription: MP3jam
OriginalFilename: mp3jamapp.Downloader.UI.exe
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Foreign.nrbr also known as:

K7AntiVirusRiskware ( 0040eff71 )
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.34630735
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.59625
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaRansom:Win32/Foreign.2a2cbc36
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.bda380
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Foreign.nrbr
BitDefenderTrojan.GenericKD.34630735
NANO-AntivirusTrojan.Win32.PepaBot.evfjvt
MicroWorld-eScanTrojan.GenericKD.34630735
TencentWin32.Trojan.Foreign.Lknl
Ad-AwareTrojan.GenericKD.34630735
SophosMal/Generic-S
ComodoMalware@#q2nht1bgdqm4
BitDefenderThetaGen:NN.ZexaF.34170.Eq0@am7XW2fi
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_HPURSNIF.SMZD2
McAfee-GW-EditionGenericRXDP-EQ!A44D8D3BDA38
FireEyeGeneric.mg.a44d8d3bda38076a
EmsisoftTrojan.GenericKD.34630735 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Yakes.ahja
AviraHEUR/AGEN.1128675
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.22CFB06
MicrosoftTrojanDropper:Win32/Ropest.A
ArcabitTrojan.Generic.D2106C4F
GDataTrojan.GenericKD.34630735
Acronissuspicious
McAfeeGenericRXDP-EQ!A44D8D3BDA38
MAXmalware (ai score=98)
VBA32Trojan-Ransom.Foreign
MalwarebytesMachineLearning/Anomalous.97%
PandaTrj/CI.A
TrendMicro-HouseCallTSPY_HPURSNIF.SMZD2
RisingTrojan.Generic@ML.92 (RDML:FLFpaRlVqgQ0pUcmhhzumQ)
YandexTrojan.GenAsa!4F353IYRLXk
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.FYCV!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Foreign.nrbr?

Trojan-Ransom.Win32.Foreign.nrbr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment