Malware

About “Win32/RA-based.NFA” infection

Malware Removal

The Win32/RA-based.NFA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/RA-based.NFA virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Operates on local firewall’s policies and settings
  • Attempts to disable UAC
  • The sample wrote data to the system hosts file.
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Uses suspicious command line tools or Windows utilities

Related domains:

wrs41.winshipway.com
ca91-1.winshipway.com

How to determine Win32/RA-based.NFA?


File Info:

crc32: 0679EDC1
md5: 68e871fb6f005f573658193b28d2c70c
name: 68E871FB6F005F573658193B28D2C70C.mlw
sha1: cdd99af3056e07e265ea90a91bfb589bf14faf0f
sha256: 4e229ef28f01bb90d24d69feb24b64c1995f449dd05f7666894ecade202f9946
sha512: 52cbc4830d0b9e55e4271e0a6a33e7677d2091b66e520e042835394cdae8a7e93e8d27851adc7bf59dcc3e47cf75800e1515ec14e90cfb845b8c2106f0e67c03
ssdeep: 24576:B4lavt0LkLL9IMixoEg5acAaI57Nuq9MmCS:Qkwkn9IMH5acAb57YaPCS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Win32/RA-based.NFA also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.DownLoader13.27068
MicroWorld-eScanTrojan.GenericKD.30371188
FireEyeGeneric.mg.68e871fb6f005f57
Qihoo-360Win32/Trojan.Ransom.de2
ALYacTrojan.GenericKD.30371188
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004fb3821 )
BitDefenderTrojan.GenericKD.30371188
K7GWTrojan ( 004fb3821 )
Cybereasonmalicious.b6f005
BitDefenderThetaAI:Packer.0C17CF7117
CyrenW32/Agent.AFI.gen!Eldorado
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallHackTool.Win32.RemoteAdmin.AB
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Agent-1383156
KasperskyTrojan-Ransom.Win32.Blocker.hgll
NANO-AntivirusTrojan.Win32.Blocker.eyrnmw
AegisLabTrojan.Win32.Blocker.j!c
TencentMalware.Win32.Gencirc.10b7d901
Ad-AwareTrojan.GenericKD.30371188
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1134167
VIPRETrojan.Win32.Generic!BT
TrendMicroHackTool.Win32.RemoteAdmin.AB
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
EmsisoftTrojan.GenericKD.30371188 (B)
IkarusTrojan.Win32.RA
AviraHEUR/AGEN.1134167
MAXmalware (ai score=98)
MicrosoftTrojan:Win32/Occamy.B
ArcabitTrojan.Generic.D1CF6D74
ZoneAlarmTrojan-Ransom.Win32.Blocker.hgll
GDataTrojan.GenericKD.30371188
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Blocker.R270229
McAfeeGenericR-EOT!68E871FB6F00
TACHYONRansom/W32.Blocker.1116160
MalwarebytesMalware.AI.4283313691
APEXMalicious
ESET-NOD32Win32/RA-based.NFA
FortinetRiskware/Nt110
AVGWin32:Trojan-gen
Paloaltogeneric.ml
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/RA-based.NFA?

Win32/RA-based.NFA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment