Ransom Trojan

What is “Trojan-Ransom.Win32.Foreign.ohbl”?

Malware Removal

The Trojan-Ransom.Win32.Foreign.ohbl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Foreign.ohbl virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Attempts to delete volume shadow copies
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Ransom.Win32.Foreign.ohbl?


File Info:

crc32: B4B91001
md5: ce4b1a3017746386a99710c62cf3f55d
name: CE4B1A3017746386A99710C62CF3F55D.mlw
sha1: f854bdbf669ad0835c352f51a6589bd4ac81908a
sha256: def0d44595ae648483729a8e3522c5352ac1a0f3f70bdd0b9d8768d1b578d51d
sha512: 85620bc89a18f7fa5dee17f56e40eba9f834af1c467413a6898b316dacfdd4b77c07ccf781c9153efc642b2df7915be7c47fe0bc0d5a48390deba8b32a2429d2
ssdeep: 6144:A6Cpd0CQ3LV6Dq3gOodt8MjWQ+XrYrdvRmG6CXqG7jneFdQr7/MI:0pd4h6Dq3y8MKQ+7YpvRmdF6eFd4MI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9Emco Software Ltd. 2000 - 2014 KG and its Licensors
InternalName: Games
FileVersion: 3.4.4.3
CompanyName: Emco Software Ltd.
PrivateBuild: 3.4.4.3
LegalTrademarks: Copyright xa9Emco Software Ltd. 2000 - 2014 KG and its Licensors
Comments: Iteration Resurcemanager Particulary
ProductName: Games
ProductVersion: 3.4.4.3
FileDescription: Iteration Resurcemanager Particulary
OriginalFilename: Games
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Foreign.ohbl also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransomware.GenericKDS.41492710
Qihoo-360Win32/Trojan.Foreign.HwoCPMsA
McAfeeArtemis!CE4B1A301774
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Foreign.tpXl
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderTrojan.Ransomware.GenericKDS.41492710
K7GWTrojan ( 00519f781 )
K7AntiVirusTrojan ( 00519f781 )
CyrenW32/Trojan.IPNZ-0388
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.Foreign.ohbl
AlibabaRansom:Win32/Foreign.0ad6cebf
NANO-AntivirusTrojan.Win32.Filecoder.ftzxrn
Ad-AwareTrojan.Ransomware.GenericKDS.41492710
TACHYONRansom/W32.Foreign.407552
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Crysis.bfj
DrWebTrojan.Encoder.3953
ZillyaTrojan.Foreign.Win32.58931
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
FireEyeGeneric.mg.ce4b1a3017746386
EmsisoftTrojan.Ransomware.GenericKDS.41492710 (B)
IkarusTrojan-Ransom.GandCrab
AviraTR/AD.Crysis.bfj
MicrosoftTrojan:Win32/Azorult!ml
ArcabitTrojan.Ransomware.GenericS.D27920E6
ZoneAlarmTrojan-Ransom.Win32.Foreign.ohbl
GDataTrojan.Ransomware.GenericKDS.41492710
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C3351439
BitDefenderThetaGen:NN.ZexaF.34590.yq0@aiVD7qli
ALYacTrojan.Ransomware.GenericKDS.41492710
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Ransom.D
ESET-NOD32Win32/Filecoder.Crysis.P
RisingRansom.Foreign!8.292 (CLOUD)
YandexTrojan.Foreign!pxswTeZyKWg
eGambitUnsafe.AI_Score_100%
FortinetW32/Foreign.OHBL!tr.ransom
AVGWin32:Trojan-gen
Cybereasonmalicious.017746
Paloaltogeneric.ml
MaxSecureTrojan.Malware.74446248.susgen

How to remove Trojan-Ransom.Win32.Foreign.ohbl?

Trojan-Ransom.Win32.Foreign.ohbl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment