Ransom Trojan

Trojan-Ransom.Win32.Blocker.bdah removal tips

Malware Removal

The Trojan-Ransom.Win32.Blocker.bdah is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.bdah virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Ransom.Win32.Blocker.bdah?


File Info:

crc32: CF9A996E
md5: 269555ae7670365019c8fe1ec88daa49
name: 269555AE7670365019C8FE1EC88DAA49.mlw
sha1: 1fabd37641e8508a349fdb18c6f135336789d4bd
sha256: b18c100ed8d45a2b4d90eba0c6dcfcca644ead4d80058a344f7fc757b880fea1
sha512: 3dc3f78656f6cbe59f26feb72475087857581d5d086003397db6cf754c05efdf1573e7434f7dab5dd52363ea42aad8a76fef329ff548a4101c5ec286bacef519
ssdeep: 1536:+g4XQ7qOz1fDdUcXTuvb0MJ2OwpZyCWA2zHgKO9l/ZUZo2jiWoiI:LhdBevlJl212jgKO9l/wo2jBoB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Blocker.bdah also known as:

DrWebBackDoor.Rukap.180
CylanceUnsafe
SangforRansom.Win32.Blocker.bdah
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Blocker.38fae5f6
Cybereasonmalicious.641e85
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Pyteconte-1
KasperskyTrojan-Ransom.Win32.Blocker.bdah
NANO-AntivirusTrojan.Win32.Blocker.bpxyvq
TencentWin32.Trojan.Blocker.Hrpd
SophosMal/Generic-S
ComodoBackdoor.Win32.Zelug.ER@655obk
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.269555ae76703650
JiangminTrojan/Blocker.hcj
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASMalwS.1925AB
KingsoftWin32.Heur.KVMH019.a.(kcloud)
MicrosoftTrojan:Win32/Occamy.CB1
AegisLabTrojan.Win32.Blocker.j!c
ZoneAlarmTrojan-Ransom.Win32.Blocker.bdah
McAfeeArtemis!269555AE7670
MAXmalware (ai score=99)
VBA32Hoax.Blocker
PandaGeneric Malware
YandexTrojan.Blocker!tLypsrLHUxM
IkarusTrojan.Injector
FortinetW32/Blocker.BDAI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASOkA

How to remove Trojan-Ransom.Win32.Blocker.bdah?

Trojan-Ransom.Win32.Blocker.bdah removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment