Ransom Trojan

Trojan-Ransom.Win32.Blocker.cinl removal guide

Malware Removal

The Trojan-Ransom.Win32.Blocker.cinl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.cinl virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Trojan-Ransom.Win32.Blocker.cinl?


File Info:

name: 724C2EF9F0F5FD40FD03.mlw
path: /opt/CAPEv2/storage/binaries/038352c2e89723f27743ead09bed15edeaf0d482023ce226ba8a2fb5ab6fd3a4
crc32: 7B0CFE1A
md5: 724c2ef9f0f5fd40fd0347e31e15db34
sha1: 6a57905180892a4f8aa4b76c0ce4bc3bf05f46a9
sha256: 038352c2e89723f27743ead09bed15edeaf0d482023ce226ba8a2fb5ab6fd3a4
sha512: fa2f8cff896fb3d929ffe3306931f25996908cb5b0a3a45b043b49ec87f25ae23a20ca1c86d9ff9569018ebb258698a65cfb54165d92b1d6a90180d815edef9c
ssdeep: 24576:CQi0l81pGT0Qh0+b0MAcJTaAeKN8Ukl7uh:C9uskoaf0MJJTtNEU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14C15231797A84938E212E5B01CB7D0112F1B7A267FB4218074EE2A5F7FBB5C1C6197D2
sha3_384: cd5a3af61ea89f6a193775fcd0720afa020a9652434e3e3528c3b576ca0ff35dd50c849c74f55609f25b9d9c934061d6
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: My Social Color 4.8 Setup
FileVersion:
LegalCopyright:
ProductName: My Social Color 4.8
ProductVersion: 4.7
Translation: 0x0000 0x04b0

Trojan-Ransom.Win32.Blocker.cinl also known as:

LionicTrojan.Win32.Blocker.j!c
Elasticmalicious (moderate confidence)
CAT-QuickHealPUA.Hightechma.Gen
McAfeeArtemis!724C2EF9F0F5
CylanceUnsafe
APEXMalicious
KasperskyTrojan-Ransom.Win32.Blocker.cinl
ComodoMalware@#bmplnurx814f
DrWebTrojan.DownLoader15.37359
ZillyaTrojan.Blocker.Win32.11608
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.cc
WebrootW32.Malware.Heur
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftProgram:Win32/Wacapew.C!ml
AhnLab-V3Trojan/Win32.Blocker.R85799
IkarusTrojan.Ransom
FortinetW32/Blocker.CINL!tr
PandaTrj/CI.A

How to remove Trojan-Ransom.Win32.Blocker.cinl?

Trojan-Ransom.Win32.Blocker.cinl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment