Ransom Trojan

Trojan.Ransom.BLV information

Malware Removal

The Trojan.Ransom.BLV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.BLV virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Anomalous binary characteristics

How to determine Trojan.Ransom.BLV?


File Info:

crc32: B9E5B642
md5: 359de5c3261cedc7a356ba2e16e4b902
name: 359DE5C3261CEDC7A356BA2E16E4B902.mlw
sha1: 3bcfea2df76062871aff0e4d466bf9ec959bdc85
sha256: dd0eb482668391021097fdc7f0a4286303d5be683cdda8085065872f5016c0f3
sha512: 13d2a29c6c7afb995ada9d9e0747a3c45f10618bea31efdb8d2b93c504de4375264be14a95bb0f3a1d5c8dbdcfbde93f26f4db79334924c7a851d15a50fcecf7
ssdeep: 6144:U5tCO/boAn8IHRXLNbJLDHhuzrsEjjFF5bBNi63lkQGf3dwR:ycODoLIxXpbJRwxNjBNi+lkQgOR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Ransom.BLV also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005018f51 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10194
CynetMalicious (score: 85)
CAT-QuickHealTrojan.Generic
ALYacTrojan.Ransom.BLV
CylanceUnsafe
ZillyaTrojan.GenKryptik.Win32.5643
SangforTrojan.Win32.Glupteba.ml
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Injector.caf4fc38
K7GWTrojan ( 005018f51 )
Cybereasonmalicious.3261ce
CyrenW32/Kryptik.CJT.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DNOE
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Crusis-6238544-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.BLV
NANO-AntivirusTrojan.Win32.Scarsi.emcgnd
MicroWorld-eScanTrojan.Ransom.BLV
TencentMalware.Win32.Gencirc.114a7c10
Ad-AwareTrojan.Ransom.BLV
SophosMal/Generic-S
ComodoMalware@#scea4o1ydx21
BitDefenderThetaGen:NN.ZexaF.34628.uuZ@aScM1En
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PB221
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.fc
FireEyeGeneric.mg.359de5c3261cedc7
EmsisoftTrojan.Ransom.BLV (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Scarsi.afp
WebrootW32.Ransom.Gen
AviraHEUR/AGEN.1111554
eGambitUnsafe.AI_Score_94%
KingsoftWin32.Troj.Ransom.v.(kcloud)
MicrosoftTrojan:Win32/Glupteba!ml
ArcabitTrojan.Ransom.BLV
AegisLabTrojan.Win32.Crusis.tonB
GDataTrojan.Ransom.BLV
AhnLab-V3Malware/Win32.Generic.C1834337
McAfeeGenericRXBI-CF!359DE5C3261C
MAXmalware (ai score=100)
VBA32Trojan.Encoder
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PB221
RisingTrojan.Injector!8.C4 (CLOUD)
YandexTrojan.GenAsa!5EM7rjUuyUY
IkarusTrojan.Win32.Injector
FortinetW32/Injector.AJAR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.97a

How to remove Trojan.Ransom.BLV?

Trojan.Ransom.BLV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment