Ransom Trojan

What is “Trojan-Ransom.Win32.Foreign.oewz”?

Malware Removal

The Trojan-Ransom.Win32.Foreign.oewz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Foreign.oewz virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Detects Bitdefender Antivirus through the presence of a library
  • Detects the presence of Wine emulator via function name
  • Enumerates services, possibly for anti-virtualization
  • Deletes its original binary from disk
  • Attempts to remove evidence of file being downloaded from the Internet
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Exhibits behavior characteristics of BetaBot / Neurevt malware
  • Creates a hidden or system file
  • Attempts to identify installed analysis tools by a known file location
  • Attempts to identify installed AV products by registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a device
  • Detects VirtualBox through the presence of a file
  • Detects VMware through the presence of a device
  • Detects VMware through the presence of a file
  • Detects VMware through the presence of a registry key
  • Attempts to modify browser security settings
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to disable browser security warnings
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Ransom.Win32.Foreign.oewz?


File Info:

crc32: 3A060740
md5: 4fe4c74e95228ae422fb642b2cf2c4c6
name: 4FE4C74E95228AE422FB642B2CF2C4C6.mlw
sha1: 30ccc2bd4989e3a9078710c65b0c505988f35392
sha256: 6e74b5b5f823200dd831a8894417b8b4e24bd66a17e7867b5cbfb4ac8b3497a5
sha512: 0b1b1e1c233991af25dd56bfecffc882467ede973d34b64b2a842965acde35e70be19c68807e0609dda3befde7453e13f15b64242618f50b2d45d979bc98fcce
ssdeep: 12288:vNXWVm138YEFNODG2KlHrtuvAZ8WF1A8W9:vn138X1L4ADM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: RonyaSoft Copyright xa9 2000 - 2014 KG and its Licensors
InternalName: Poulsen
CompanyName: RonyaSoft
PrivateBuild: 4.2.7.2
LegalTrademarks: RonyaSoft Copyright xa9 2000 - 2014 KG and its Licensors
Comments: Int32 Select Retrieve Dictionary J Representative
ProductName: Poulsen
Languages: English
ProductVersion: 4.2.7.2
FileDescription: Int32 Select Retrieve Dictionary J Representative
OriginalFilename: Poulsen.exe
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Foreign.oewz also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Foreign.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Betabot.263
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.AntiSandbox.GenericKDS.31654502
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.58546
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Foreign.1fad94a2
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.e95228
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.GZFV
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.Foreign.oewz
BitDefenderTrojan.AntiSandbox.GenericKDS.31654502
NANO-AntivirusTrojan.Win32.Betabot.fmsjqq
MicroWorld-eScanTrojan.AntiSandbox.GenericKDS.31654502
TencentWin32.Trojan.Foreign.Piue
Ad-AwareTrojan.AntiSandbox.GenericKDS.31654502
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34236.Ny0@a056QFdi
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_HPURSNIF.SMZD2
McAfee-GW-EditionBehavesLike.Win32.Dropper.jc
FireEyeGeneric.mg.4fe4c74e95228ae4
EmsisoftTrojan.AntiSandbox.GenericKDS.31654502 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Foreign.fhq
WebrootW32.Malware.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2A7AC44
MicrosoftTrojan:Win32/CryptInject
GDataTrojan.AntiSandbox.GenericKDS.31654502
TACHYONRansom/W32.Foreign.645120
AhnLab-V3Spyware/Win32.Hpursnif.C3001554
Acronissuspicious
McAfeeArtemis!4FE4C74E9522
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Foreign
MalwarebytesTrojan.Ursnif
PandaTrj/RnkBend.A
TrendMicro-HouseCallTSPY_HPURSNIF.SMZD2
YandexTrojan.Foreign!OJuWm9gj4rE
IkarusTrojan-Ransom.GandCrab
MaxSecureTrojan.Malware.73761530.susgen
FortinetW32/Foreign.OEWZ!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Foreign.oewz?

Trojan-Ransom.Win32.Foreign.oewz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment