Ransom Trojan

How to remove “Trojan-Ransom.Win32.Blocker.gewy”?

Malware Removal

The Trojan-Ransom.Win32.Blocker.gewy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.gewy virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)

How to determine Trojan-Ransom.Win32.Blocker.gewy?


File Info:

crc32: 56B97D69
md5: 5473bfa579f5458f8016e9b1b00a94f5
name: 5473BFA579F5458F8016E9B1B00A94F5.mlw
sha1: b5da7ead62b83b5ed22c506588986bd55b4cc75e
sha256: ca29ee8f0621f3e301306b3046456c9ca49fe06f4fa29af6d4b16f128d0f9a4a
sha512: 8d4a9d513ac8051eb80489fc5d7ea1aec93dba6bb048e39f64fb213695657b678b9fae6de8487b480d1220c649f0c1ae271e9505b3cdbd9aa7358927e68f6f93
ssdeep: 12288:Ctb20Qc3lT7af41ePBRYuQLKpqeUhbTv5OFgNuPPpHSga1Twqd1ujJ0ZSTq5UN6:Ctb20pkaCqT5TBWgNQ7ahvdTSjN6A
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan-Ransom.Win32.Blocker.gewy also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3991 )
LionicTrojan.Win32.Blocker.j!c
DrWebTrojan.KeyLogger.26163
CAT-QuickHealRansom.AutoIt.Blocker.A3
ALYacTrojan.GenericKD.2023515
CylanceUnsafe
SangforTrojan.Win32.AGEN.1000251
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Blocker.2dc326fb
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.579f54
SymantecTrojan.Gen
ESET-NOD32multiple detections
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.Blocker.gewy
BitDefenderTrojan.GenericKD.2023515
NANO-AntivirusTrojan.Win32.Blocker.dkzakv
MicroWorld-eScanTrojan.GenericKD.2023515
TencentWin32.Trojan.Blocker.Suxn
Ad-AwareTrojan.GenericKD.2023515
ComodoMalware@#69f4kiw2a36s
BitDefenderThetaAI:Packer.741013D915
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.th
FireEyeTrojan.GenericKD.2023515
EmsisoftTrojan.GenericKD.2023515 (B)
WebrootW32.Trojan.GenKD
AviraHEUR/AGEN.1100141
eGambitUnsafe.AI_Score_69%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:AutoIt/Neurevt
ZoneAlarmTrojan-Ransom.Win32.Blocker.gewy
GDataTrojan.GenericKD.2023515
AhnLab-V3Trojan/Win32.Obfuscator.C910813
McAfeeArtemis!5473BFA579F5
MAXmalware (ai score=100)
VBA32TrojanRansom.Blocker
PandaTrj/CI.A
IkarusTrojan-Ransom.Blocker
FortinetW32/Fynloski.AM!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Blocker.gewy?

Trojan-Ransom.Win32.Blocker.gewy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment