Ransom Trojan

Trojan-Ransom.Win32.Foreign.nzbs malicious file

Malware Removal

The Trojan-Ransom.Win32.Foreign.nzbs is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Foreign.nzbs virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to stop active services
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to disable Windows Defender
  • Attempts to modify or disable Security Center warnings

How to determine Trojan-Ransom.Win32.Foreign.nzbs?


File Info:

crc32: D9FC4F02
md5: 85f24e04650e9e5fa0a8bedf5d322a77
name: 85F24E04650E9E5FA0A8BEDF5D322A77.mlw
sha1: 70dcae00091e6930fc90689bfd1d48df77891019
sha256: d42ba0c7e504daf417808ecb5cceb87261885ef75eef5d1d09ef42defb5c197d
sha512: 842dbcde7d5b26985a7b274a3bbec1428a187622e75ccb0dd69fce01f547d75fb91ffb080079c6aee24ae4eb2e62cf02204ede6f49b3f87cbc9601a0a342a948
ssdeep: 6144:jt+59KOBjIXFdRXTOVbsOiC0vI9odnf5P:j0rKOBjmtlXQmNfd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2015 FileVersion
InternalName: Itins
FileVersion: 5.2.61.5
CompanyName: FileVersion
ProductName: Itins
ProductVersion: 5.2.61.5
FileDescription: Hga 4074 Civilization
OriginalFilename: Itins
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Foreign.nzbs also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 00539ed31 )
LionicTrojan.Win32.Foreign.j!c
Elasticmalicious (high confidence)
DrWebBackDoor.IRC.Bot.4257
ALYacTrojan.GenericKD.30547925
MalwarebytesMachineLearning/Anomalous.100%
ZillyaTrojan.Foreign.Win32.57698
CrowdStrikewin/malicious_confidence_60% (D)
K7GWAdware ( 00539ed31 )
Cybereasonmalicious.4650e9
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Ramnit.BV
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Foreign.nzbs
BitDefenderTrojan.GenericKD.30547925
NANO-AntivirusTrojan.Win32.Bot.eyrtyi
MicroWorld-eScanTrojan.GenericKD.30547925
TencentWin32.Virus.Ramnit.Eddy
Ad-AwareTrojan.GenericKD.30547925
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34142.yq0@aig7P!pi
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_MiliCry-1h
McAfee-GW-EditionBehavesLike.Win32.Swizzor.fh
FireEyeGeneric.mg.85f24e04650e9e5f
EmsisoftTrojan.GenericKD.30547925 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Foreign.ela
WebrootW32.Trojan.Emotet
AviraHEUR/AGEN.1110230
Antiy-AVLTrojan/Generic.ASMalwS.24DED59
MicrosoftTrojan:Win32/Skeeyah.A!rfn
GDataTrojan.GenericKD.30547925
AhnLab-V3Win-Trojan/Sagecrypt.Gen
Acronissuspicious
McAfeeArtemis!85F24E04650E
MAXmalware (ai score=99)
VBA32BScope.Trojan-Ransom.SageCrypt
PandaTrj/CI.A
TrendMicro-HouseCallMal_MiliCry-1h
RisingTrojan.Generic@ML.98 (RDML:7T42Uz+yW1VL8N7hDz4wAQ)
IkarusVirus.Win32.Ramnit
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Fareit.A
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Foreign.nzbs?

Trojan-Ransom.Win32.Foreign.nzbs removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment