Ransom Trojan

About “Trojan-Ransom.Win32.Blocker.gnve” infection

Malware Removal

The Trojan-Ransom.Win32.Blocker.gnve is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.gnve virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.Blocker.gnve?


File Info:

name: F032B115DF457AB53928.mlw
path: /opt/CAPEv2/storage/binaries/3ca2b5eddcea66f52c9c7303dbc43c1b589999969940ba7c17dfb96a0d65a5bc
crc32: 08D1279F
md5: f032b115df457ab5392868e9baabe1e4
sha1: 8d0c174b774d21ca76758fd90eb51f4e327ecb39
sha256: 3ca2b5eddcea66f52c9c7303dbc43c1b589999969940ba7c17dfb96a0d65a5bc
sha512: 90326d0234caa937da67acd877dca5984b3d2bafa860f8580b5fae61f0e418fb0dc4758beea585340cf248acd7b6eae0f105039a941e7e1866956e11748702ad
ssdeep: 192:n1c2hLi+wf1prymZT5+X4Q0P+NZoJJREqqP/LN:1cGLi+wf1AYYX4PP+NeV
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D4324B9B9F5D0221F76108B87B7712590A3EBCD3339572E7EFB278401B25692C4918E7
sha3_384: e50a0a276963ec4df7603907e5044109662dd0e1b7e889263dc190699fe66046630cd9aa578c5cdab8a43c9d33bb8d34
ep_bytes: e880040000e99ffdffff5589e589ff81
timestamp: 2012-10-29 15:49:48

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Blocker.gnve also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.451781
FireEyeGen:Variant.Zusy.451781
CAT-QuickHealTrojan.GenericRI.S30115043
MalwarebytesMalware.AI.3654172958
BitDefenderThetaGen:NN.ZexaF.36164.ayW@aS8Jlwii
CyrenW32/Blocker.L.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Small.NYG
KasperskyTrojan-Ransom.Win32.Blocker.gnve
BitDefenderGen:Variant.Zusy.451781
NANO-AntivirusTrojan.Win32.Blocker.favveo
AvastWin32:RansomX-gen [Ransom]
TencentTrojan-Ransom.Win32.Blocker.ko
TACHYONRansom/W32.Blocker.11264
DrWebTrojan.MulDrop21.58295
VIPREGen:Variant.Zusy.451781
EmsisoftGen:Variant.Zusy.451781 (B)
IkarusTrojan.Win32.Small
GDataGen:Variant.Zusy.451781
JiangminTrojan.Blocker.uxa
GoogleDetected
ArcabitTrojan.Zusy.D6E4C5
ZoneAlarmTrojan-Ransom.Win32.Blocker.gnve
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Blocker.R560620
MAXmalware (ai score=84)
PandaTrj/Genetic.gen
RisingRansom.Blocker!8.12A (TFE:5:oSUc7RfbUHO)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Wacatac.B!tr
AVGWin32:RansomX-gen [Ransom]
DeepInstinctMALICIOUS

How to remove Trojan-Ransom.Win32.Blocker.gnve?

Trojan-Ransom.Win32.Blocker.gnve removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment