Ransom

Ransom:Win32/Blocker removal

Malware Removal

The Ransom:Win32/Blocker is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Blocker virus can do?

  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Ransom:Win32/Blocker?


File Info:

crc32: C80F8ABD
md5: c4fa75fde79d74cb722d7088cf0daf31
name: C4FA75FDE79D74CB722D7088CF0DAF31.mlw
sha1: f8b95527d07d8c6af7ba5b56a3ef696f2ed92514
sha256: 259e54a16e192d2d330b16963b3a9fa66c9a80b9cb97a47e58ddf63501e5eb0e
sha512: a2f2044e9e985c1f9318e7adc12c022f5dacb2f7950e2be68351899924426d069984021f8ef229be9b959e1641bd3322fa395927d2339043052c4b94e083ec8b
ssdeep: 12288:LkxgYHEDFOhUJN+LrFuJkj8p+UOH+cqtPmEESWN:LkqYHEgheorFuJkj8QUOhqBmHSWN
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: (C) NVIDIA Corporation. All rights reserved.
InternalName: ipccommon
FileVersion:
CompanyName: NVIDIA Corporation
ProductName: NVIDIA GeForce Experience
ProductVersion: 3.20.5.70
FileDescription: NVIDIA IpcCommon
OriginalFilename: ipccommon.dll
Translation: 0x0409 0x04b0

Ransom:Win32/Blocker also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader32.59441
MicroWorld-eScanTrojan.GenericKD.44836161
FireEyeTrojan.GenericKD.44836161
McAfeeRDN/Ransom
CylanceUnsafe
SangforRansom.Win32.Blocker.mt
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.44836161
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.de79d7
CyrenW64/Trojan.MPGB-8957
SymantecTrojan.Gen.2
APEXMalicious
AvastWin64:Malware-gen
ClamAVWin.Dropper.Ymacco-9822260-0
KasperskyTrojan-Ransom.Win32.Blocker.mssz
AlibabaRansom:Win32/Blocker.6194cb20
NANO-AntivirusTrojan.Win64.Blocker.ihftth
RisingRansom.Blocker!8.12A (CLOUD)
Ad-AwareTrojan.GenericKD.44836161
SophosGeneric PUA PI (PUA)
F-SecureTrojan.TR/Blocker.ylasc
ZillyaTrojan.Blocker.Win32.63806
TrendMicroRansom_Blocker.R067C0PLA20
McAfee-GW-EditionRDN/Ransom
EmsisoftTrojan.GenericKD.44836161 (B)
IkarusTrojan.Win32.Ilgergop
AviraTR/Blocker.ylasc
MAXmalware (ai score=80)
Antiy-AVLTrojan[Dropper]/Win32.Dapato
MicrosoftRansom:Win32/Blocker
ArcabitTrojan.Generic.D2AC2541
ZoneAlarmTrojan-Ransom.Win32.Blocker.mssz
GDataTrojan.GenericKD.44836161
CynetMalicious (score: 90)
VBA32TrojanRansom.Blocker
ALYacTrojan.GenericKD.44836161
MalwarebytesMalware.AI.4246230186
PandaTrj/CI.A
TrendMicro-HouseCallRansom_Blocker.R067C0PLA20
YandexTrojan.Injuke!aqAZMDGP0yA
eGambitPE.Heur.InvalidSig
FortinetW32/Blocker.MSSZ!tr
AVGWin64:Malware-gen
CrowdStrikewin/malicious_confidence_70% (W)
Qihoo-360Win64/Ransom.Blocker.HgEASOQA

How to remove Ransom:Win32/Blocker?

Ransom:Win32/Blocker removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment