Ransom Trojan

About “Trojan-Ransom.Win32.Foreign.ntzm” infection

Malware Removal

The Trojan-Ransom.Win32.Foreign.ntzm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Foreign.ntzm virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.Foreign.ntzm?


File Info:

crc32: BC4B0FF6
md5: 33cbb26af2486f33b795b556953481a8
name: 33CBB26AF2486F33B795B556953481A8.mlw
sha1: 3755e298194eef6a7ad32181e7a0495f44614c04
sha256: 65606c9655cc74e199c546346ef6ffa68d2fefce8243cf9274512fd590c8b6c6
sha512: 8fa371e857ab65535ed7f96ba681c8e2fc522f12487792b525948e790f3fb38c3be655e16881ec279c696f3fd266b2beb5f07a4f91386f9d3a1d33545a8caf8f
ssdeep: 6144:DJSHYapgVsanFft9Y5hclqbEi1Awvnp1pnKKSguioWCliLaQ:Df8+ftO5hcl3iRvp1pnKMgliGQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Foreign.ntzm also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0051cc3d1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Cerbu.73920
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 0051cc3d1 )
Cybereasonmalicious.af2486
CyrenW32/S-d2c789ae!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.EYUK
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Ransomware.Fugrafa-9779211-0
KasperskyTrojan-Ransom.Win32.Foreign.ntzm
BitDefenderGen:Variant.Cerbu.73920
NANO-AntivirusTrojan.Win32.Kryptik.evpjua
MicroWorld-eScanGen:Variant.Cerbu.73920
TencentWin32.Trojan.Foreign.Lknz
Ad-AwareGen:Variant.Cerbu.73920
SophosMal/Ransom-EE
ComodoMalware@#3hv42unyhfhfa
BitDefenderThetaGen:NN.ZexaF.34690.yuX@a4Kl6dei
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXDZ-EC!33CBB26AF248
FireEyeGeneric.mg.33cbb26af2486f33
EmsisoftGen:Variant.Cerbu.73920 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1112598
MicrosoftPWS:Win32/Zbot
ArcabitTrojan.Cerbu.D120C0
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Cerbu.73920
AhnLab-V3Trojan/Win32.RL_Foreign.R355029
McAfeeGenericRXDZ-EC!33CBB26AF248
MAXmalware (ai score=100)
VBA32Trojan-Ransom.Foreign
MalwarebytesTrojan.Zbot
PandaTrj/GdSda.A
RisingRansom.Foreign!8.292 (CLOUD)
YandexTrojan.GenAsa!4j1703otN08
IkarusTrojan-Ransom.Foreign
FortinetW32/Kryptik.FCAB!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Foreign.ntzm?

Trojan-Ransom.Win32.Foreign.ntzm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment