Ransom Trojan

Trojan-Ransom.Win32.Blocker.epvv removal

Malware Removal

The Trojan-Ransom.Win32.Blocker.epvv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.epvv virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup

How to determine Trojan-Ransom.Win32.Blocker.epvv?


File Info:

name: 7FB57A91506976F110D7.mlw
path: /opt/CAPEv2/storage/binaries/7c2e0dd224a75a7a5a0959572ab378f52e0a0f6b9b7689c9a8cbd4f1329795ca
crc32: A3971D94
md5: 7fb57a91506976f110d7517d0b81a00b
sha1: cf31f047056c173fd468dd99ee3e45cc6831f457
sha256: 7c2e0dd224a75a7a5a0959572ab378f52e0a0f6b9b7689c9a8cbd4f1329795ca
sha512: 8e53e16a3ab0fcec34e13642eb25fb385d36584cabad5a714e05fb0933dd33785dba2e407271f5d0f8c654ee35068983ca4edd27b8e2762ddbc04adc687903a1
ssdeep: 1536:hS13yKWCzZisq8zucc7SBHbuuvskzG7mT:o1iKWmTd6t7SpuCskzG7m
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T190538E93A6C1106AE0C9E3757B37B22C731BDCE5856CE2871E25139DC917B925E7AB00
sha3_384: b90cf0086948d266f02b9917139b31f25663b07cea438db3d1644cbd55685b749ee4f083422074e129fff5fc743b952d
ep_bytes: 558bec6aff68b0f24000681050400064
timestamp: 2014-05-13 16:02:12

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Blocker.epvv also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Blocker.j!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.1680621
FireEyeGeneric.mg.7fb57a91506976f1
ALYacTrojan.GenericKD.1680621
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforSpyware.Win32.Zbot.AAU
K7AntiVirusSpyware ( 004b8cd91 )
AlibabaRansom:Win32/Blocker.5f0c793d
K7GWSpyware ( 004b8cd91 )
Cybereasonmalicious.150697
VirITTrojan.Win32.Zbot.IUM
CyrenW32/Trojan.PHBT-7037
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.AAU
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Blocker.epvv
BitDefenderTrojan.GenericKD.1680621
NANO-AntivirusTrojan.Win32.Blocker.efgyge
SUPERAntiSpywareTrojan.Agent/Gen-Festo
AvastWin32:Malware-gen
RisingTrojan.Spy.Win32.Blocker.ca (CLOUD)
Ad-AwareTrojan.GenericKD.1680621
TACHYONTrojan/W32.Blocker.62464.I
EmsisoftTrojan.GenericKD.1680621 (B)
ComodoMalware@#21a82tq7pv603
DrWebTrojan.DownLoader11.10111
ZillyaTrojan.Blocker.Win32.18367
TrendMicroTROJ_SPNR.14HS14
McAfee-GW-EditionGeneric.rs
SophosML/PE-A + Mal/Generic-L
GDataWin32.Trojan.Agent.DU7EA2
JiangminTrojan/Blocker.jfh
WebrootW32.Malware.Gen
AviraTR/Agent.62464.68
Antiy-AVLTrojan[Ransom]/Win32.Blocker
KingsoftWin32.Troj.Undef.(kcloud)
ViRobotSpyware.Ransom.Blocker.62464
MicrosoftTrojanDownloader:Win32/Upatre
CynetMalicious (score: 100)
McAfeeGeneric.rs
MAXmalware (ai score=100)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesTrojan.Agent.OL
TrendMicro-HouseCallTROJ_SPNR.14HS14
TencentWin32.Trojan.Blocker.Ammn
YandexTrojan.Blocker!21XLAHOrvP0
IkarusTrojan-Spy.Zbot
eGambitGeneric.Trojan
FortinetW32/Blocker.AAU!tr
BitDefenderThetaGen:NN.ZexaF.34182.dqW@aGEWLdei
AVGWin32:Malware-gen
PandaTrj/WLT.A
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.7486098.susgen

How to remove Trojan-Ransom.Win32.Blocker.epvv?

Trojan-Ransom.Win32.Blocker.epvv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment