Ransom Trojan

Trojan-Ransom.Win32.Blocker.blhe removal guide

Malware Removal

The Trojan-Ransom.Win32.Blocker.blhe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.blhe virus can do?

  • Executable code extraction
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

applesupportforums.com

How to determine Trojan-Ransom.Win32.Blocker.blhe?


File Info:

crc32: F8FA320B
md5: 59cb7644511ded6089272d360e2622f5
name: 59CB7644511DED6089272D360E2622F5.mlw
sha1: 662bce7197b8b517b0dd924805dfc679e429558f
sha256: 171ab79cd58e2be6aeada2c137c8ab74eecf082ae2a80358e84fccd254bf760b
sha512: 29217d0c049c49dbbdc290ad288c56ba7019c23b5619a9d9f0138d8f17e7426e10ae779a53c01fe218f5c3a855273603e195673cda23eca4ce079a214df1f5db
ssdeep: 3072:VuKnWFnzBHv/xWFsg8WatM1gjWPE5ac0nrQ1k:VuNBHng5HaiRrQ1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: 58685018
FileVersion: 1.00
CompanyName: Microsoft
ProductName: Microsoft
ProductVersion: 1.00
OriginalFilename: 58685018.exe

Trojan-Ransom.Win32.Blocker.blhe also known as:

BkavW32.AIDetect.malware1
K7AntiVirusNetWorm ( 700000151 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader4.49040
CynetMalicious (score: 100)
CAT-QuickHealTrojan.VBCrypt.MF.1942
ALYacGen:Trojan.Chinky.2
CylanceUnsafe
ZillyaTrojan.Spy.Win32.625
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Blocker.5dbbfc14
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.4511de
SymantecW32.Cambot
ESET-NOD32a variant of Win32/Spy.VB.NXM
APEXMalicious
AvastWin32:Cambot-AN [Wrm]
ClamAVWin.Worm.Vobfus-7541859-0
KasperskyTrojan-Ransom.Win32.Blocker.blhe
BitDefenderGen:Trojan.Chinky.2
NANO-AntivirusTrojan.Win32.Blocker.ebyqhy
MicroWorld-eScanGen:Trojan.Chinky.2
TencentWin32.Trojan.Blocker.Sysh
Ad-AwareGen:Trojan.Chinky.2
SophosMal/Generic-R + Mal/Agent-ADJ
ComodoMalware@#1xwb3pgd1rhx1
BitDefenderThetaAI:Packer.B10428911C
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.VBObfus.ch
FireEyeGeneric.mg.59cb7644511ded60
EmsisoftGen:Trojan.Chinky.2 (B)
SentinelOneStatic AI – Malicious PE
JiangminWorm/VBNA.hcgx
AviraTR/Dropper.Gen
eGambitGeneric.PSW
Antiy-AVLTrojan/Generic.ASMalwS.184037B
MicrosoftWorm:Win32/Cambot.A
GDataGen:Trojan.Chinky.2
TACHYONRansom/W32.VB-Blocker.126976.C
McAfeeGenericRXAA-AA!59CB7644511D
MAXmalware (ai score=98)
VBA32Hoax.Blocker
MalwarebytesGeneric.Worm.Agent.DDS
PandaGeneric Malware
YandexTrojan.GenAsa!0lMHpjuy6LA
IkarusP2P-Worm.Win32.BlackControl
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBNA.BH!worm
AVGWin32:Cambot-AN [Wrm]
Paloaltogeneric.ml
Qihoo-360Win32/Worm.Cambot.HgIASOQA

How to remove Trojan-Ransom.Win32.Blocker.blhe?

Trojan-Ransom.Win32.Blocker.blhe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment