Ransom Trojan

Trojan-Ransom.Win32.Blocker.blhy removal instruction

Malware Removal

The Trojan-Ransom.Win32.Blocker.blhy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.blhy virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Ransom.Win32.Blocker.blhy?


File Info:

crc32: D005FDB4
md5: e7227b984a8446a474d66b62882136da
name: E7227B984A8446A474D66B62882136DA.mlw
sha1: 92529434f18efbf3b373935ddd09dc54ae1dd1f4
sha256: 0906075ab33b7b609180deb54219fd610718095b9857006861572b55740cd54d
sha512: 9d9594f4ced16fe7d1955b7f8accd44fcf56b89b751c74aa199b41bc4a5d0b24613b6d8e51c1abdd24be970dddf16ed53bc078fa98500be702693e52cc15e084
ssdeep: 1536:G8HDtkDiu/IX84We7RV9bOrWHhBpNvI5Sg/T:GoaDiuwX84We7RDnBrvQSQT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: DataDLL
FileVersion: 12.43.0054
CompanyName: SunCorporation Inc.
Comments: Cj6OFyg
ProductName: Java(TM)UpdateStart
ProductVersion: 12.43.0054
FileDescription: Windows Hizmetleri Ana Bilgisayar x130x15flemi
OriginalFilename: DataDLL.exe

Trojan-Ransom.Win32.Blocker.blhy also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 0055e3db1 )
LionicTrojan.Win32.Blocker.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen3.5900
CynetMalicious (score: 100)
ALYacGen:Variant.Graftor.Elzob.12855
CylanceUnsafe
ZillyaTrojan.Spy.Win32.1666
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Blocker.2581aecd
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.84a844
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.VB.NGZ
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.LokiBot-7601662-0
KasperskyTrojan-Ransom.Win32.Blocker.blhy
BitDefenderGen:Variant.Graftor.Elzob.12855
NANO-AntivirusTrojan.Win32.Miser.covkkp
MicroWorld-eScanGen:Variant.Graftor.Elzob.12855
TencentMalware.Win32.Gencirc.10bfa961
Ad-AwareGen:Variant.Graftor.Elzob.12855
SophosML/PE-A
ComodoTrojWare.Win32.Miser.B@36gnb2
BitDefenderThetaGen:NN.ZevbaF.34170.mm3@aWpd6Dhi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Fareit.dz
FireEyeGeneric.mg.e7227b984a8446a4
EmsisoftGen:Variant.Graftor.Elzob.12855 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.1899C03
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Miser.A
ZoneAlarmTrojan-Ransom.Win32.Blocker.blhy
GDataGen:Variant.Graftor.Elzob.12855
AhnLab-V3Worm/Win32.VBNA.R13846
McAfeeGenericRXHK-AJ!E7227B984A84
MAXmalware (ai score=100)
VBA32Trojan.VBRA.01835
MalwarebytesTrojan.KeyLogger
PandaTrj/CI.A
RisingTrojan.Miser!1.6766 (CLASSIC)
YandexTrojan.Blocker!blBXeV2Mh8Y
IkarusTrojan.Win32.Miser
FortinetW32/KeyLogger.VBY!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Blocker.blhy?

Trojan-Ransom.Win32.Blocker.blhy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment