Ransom

About “Ransom:Win32/Blocker!pz” infection

Malware Removal

The Ransom:Win32/Blocker!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Blocker!pz virus can do?

  • A file was accessed within the Public folder.
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Touches a file containing cookies, possibly for information gathering

How to determine Ransom:Win32/Blocker!pz?


File Info:

name: 71923AEFCB6B074166FA.mlw
path: /opt/CAPEv2/storage/binaries/d2e5ddb6661ca0993b195975323171a5b44fbd323e294fd95db2b41096f36a3b
crc32: AB8B3E7E
md5: 71923aefcb6b074166fa96a872a21b1c
sha1: f83c75cc8a3090d9639111cfc360ae596393ac90
sha256: d2e5ddb6661ca0993b195975323171a5b44fbd323e294fd95db2b41096f36a3b
sha512: 3e617ab81b93ae4a027cf784a94566784fed5877b454728c3f794a9ad5ccba8bad0223bef859e8474774ea11c6ef1a882c9f88dfd4961a29da08a5e3376b58a3
ssdeep: 49152:bDTOn6XJLrduEyztsR7OQzQzAmjqamm173f:bPO6dd/yzt67OU7apv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A0A5137AF5D18437C1336E7CDC6B6754A83A7EE01D28208A7BE81C499F39781352A2D7
sha3_384: aeb4ff23ea507e16ed0d49a73db64dd145a0f57020d4a7360d9474f27575338d41cc454f40d89cd710c09c6a620915de
ep_bytes: 558becb9280000006a006a004975f953
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Ransom:Win32/Blocker!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Blocker.tpV6
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Symmi.27009
ClamAVWin.Trojan.Mbrlock-9779766-0
FireEyeGeneric.mg.71923aefcb6b0741
CAT-QuickHealRansom.Blocker.19974
SkyhighBehavesLike.Win32.Generic.tc
McAfeeGenericRXDE-WO!71923AEFCB6B
Cylanceunsafe
ZillyaTrojan.Blocker.Win32.98725
SangforRansom.Win32.Save.a
K7AntiVirusTrojan ( 00548e051 )
AlibabaTrojan:Win32/Starter.ali1001008
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.c8a309
ArcabitTrojan.Symmi.D6981
BitDefenderThetaAI:Packer.6C5C7DC621
VirITBackdoor.RBot.BZ
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.ERFT
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.fqcy
BitDefenderGen:Variant.Symmi.27009
NANO-AntivirusTrojan.Win32.Dapato.bsjzfg
AvastWin32:MBRlock-DV [Trj]
TencentTrojan.Win32.Blocker.zg
EmsisoftGen:Variant.Symmi.27009 (B)
F-SecureDropper.DR/Delphi.Gen
DrWebTrojan.DownLoader6.7779
VIPREGen:Variant.Symmi.27009
Trapminemalicious.high.ml.score
SophosTroj/Agent-BCQB
IkarusTrojan.Win32.Agent
JiangminTrojanDropper.Dapato.gti
WebrootW32.Trojan.Gen
GoogleDetected
AviraDR/Delphi.Gen
Antiy-AVLGrayWare/Win32.Kryptik.ahho
XcitiumTrojWare.Win32.Injector.HO@82j6jo
MicrosoftRansom:Win32/Blocker!pz
ZoneAlarmTrojan-Ransom.Win32.Blocker.fqcy
GDataGen:Variant.Symmi.27009
VaristW32/Injector.OZVT-2500
AhnLab-V3Dropper/Win32.Dapato.R83155
VBA32TrojanRansom.Blocker
ALYacGen:Variant.Symmi.27009
MAXmalware (ai score=81)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
RisingRansom.Blocker!8.12A (TFE:4:U66Qx1HZP5U)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Dropper.XUQ!tr
AVGWin32:MBRlock-DV [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom:Win32/Blocker!pz?

Ransom:Win32/Blocker!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment