Ransom Trojan

Trojan-Ransom.Win32.Blocker.cjzj removal guide

Malware Removal

The Trojan-Ransom.Win32.Blocker.cjzj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.cjzj virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Drops a binary and executes it
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Creates a copy of itself

How to determine Trojan-Ransom.Win32.Blocker.cjzj?


File Info:

crc32: D5590651
md5: bc11c93f1b6dc74bf4804a35b34d9267
name: BC11C93F1B6DC74BF4804A35B34D9267.mlw
sha1: a18c25ed1282f56225d21c6460ffaaf16ae0d965
sha256: a2bc3059283d7cc7bc574ce32cb6b8bfd27e02ac3810a21bd3a9b84c17f18a72
sha512: c1e29195cd7ec50ae233318dcd149a6430fae3feb1f049c75083ee8879ea4733a09a985325d8448661d0c59a0a509ce9baaab174cb114d6ba2f908f63c819521
ssdeep: 12288:GebREpUV8gO1Axt4Kkp7vSCfnuf9Ooj0N:ZbepUV8gOit4KW79aOoQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2002-2009 Woodround Corporation. All rights reserved.
InternalName: cardpus.exe
FileVersion: 10.3.346.213
CompanyName: Woodround Corp.
SpecialBuild: Public
LegalTrademarks: Copyright (C) 2000-2007 Woodround Corporation. All rights reserved.
ProductName: Woodround Earthbring
ProductVersion: 10.3.346.213
FileDescription: Woodround Earthbring
OriginalFilename: cardpus.exe
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Blocker.cjzj also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0040f6691 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader10.20428
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Crilock.A
ALYacTrojan.GenericKDV.1270078
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.11463
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Starter.ali2000005
K7GWTrojan ( 0040f6691 )
Cybereasonmalicious.f1b6dc
CyrenW32/Trojan.GAJP-2126
SymantecRansom.Cryptolock!g4
ESET-NOD32Win32/Filecoder.BQ
ZonerTrojan.Win32.20131
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.cjzj
BitDefenderTrojan.GenericKDV.1270078
NANO-AntivirusTrojan.Win32.Blocker.cqjuzu
ViRobotTrojan.Win32.S.Ransom.708608
MicroWorld-eScanTrojan.GenericKDV.1270078
TencentWin32.Trojan.Blocker.Pfiv
Ad-AwareTrojan.GenericKDV.1270078
SophosMal/Generic-R + Mal/Ransom-BZ
ComodoMalware@#3109uvwwl6ppv
BitDefenderThetaGen:NN.ZexaF.34670.Rq0@aqWGI2hi
VIPRETrojan.Win32.Zbot.ata (v)
TrendMicroTROJ_CRILOCK.AA
McAfee-GW-EditionGeneric.ru
FireEyeGeneric.mg.bc11c93f1b6dc74b
EmsisoftTrojan.GenericKDV.1270078 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Agent.hmls
WebrootTrojan.Crilock.A
AviraTR/Crypt.ZPACK.12461
eGambitGeneric.Malware
Antiy-AVLTrojan[Ransom]/Win32.Blocker
MicrosoftRansom:Win32/Crilock.A
AegisLabTrojan.Win32.Blocker.j!c
GDataWin32.Trojan.Agent.8T2DYF
TACHYONTrojan/W32.Blocker.708608.B
AhnLab-V3Trojan/Win32.Blocker.C199566
McAfeeGeneric.ru
MAXmalware (ai score=100)
VBA32Hoax.Blocker
PandaTrj/WLT.A
TrendMicro-HouseCallTROJ_CRILOCK.AA
RisingTrojan.Spy.Win32.Crilock.b (CLOUD)
YandexTrojan.Blocker!Ji4+v3NOOKo
IkarusTrojan-Spy.Zbot
MaxSecureTrojan.Malware.6433862.susgen
FortinetW32/KRYPTIK.PDA!tr
AVGWin32:Malware-gen
Qihoo-360Win32/Ransom.Blocker.HwcBINsA

How to remove Trojan-Ransom.Win32.Blocker.cjzj?

Trojan-Ransom.Win32.Blocker.cjzj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment