Ransom Trojan

Trojan-Ransom.Win32.Blocker.gqmj (file analysis)

Malware Removal

The Trojan-Ransom.Win32.Blocker.gqmj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.gqmj virus can do?

  • Creates RWX memory
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.Blocker.gqmj?


File Info:

crc32: 4446920A
md5: 42264c8459540c094079d576a7e6465e
name: 42264C8459540C094079D576A7E6465E.mlw
sha1: 8f34b5dd46e979ecde1bb07d7583e3337e96cf59
sha256: 7a69cf34e8259a89c12ebae7fed7bfe906590e5e12434cefbecd49588f2ed318
sha512: db6715ffc32442315f9a38ce174c7c4e0c4058e3ca59be68d60354f3f280cc164738a014df0e24c6bde568ab4dee320a87718ad1a8c1afd3f1031b10925a6db9
ssdeep: 192:PWhmcVY2G0jLQMd9Kx27e6ith0mtCYEUbfo:AmcVYLIW2xImYv
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: VIRUS_XERQ.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: VIRUS_XERQ.exe

Trojan-Ransom.Win32.Blocker.gqmj also known as:

DrWebTrojan.DownLoader12.58986
FireEyeGeneric.mg.42264c8459540c09
CylanceUnsafe
AegisLabTrojan.Win32.Blocker.j!c
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.d46e97
BitDefenderThetaGen:NN.ZemsilF.34608.am0@aixbGKe
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.gqmj
NANO-AntivirusTrojan.Win32.Blocker.dpebox
RisingRansom.Blocker!8.12A (CLOUD)
McAfee-GW-EditionArtemis!Trojan
SentinelOneStatic AI – Malicious PE
MicrosoftBackdoor:Win32/Bladabindi!ml
AhnLab-V3ASD.Reputation.C866498
ZoneAlarmTrojan-Ransom.Win32.Blocker.gqmj
McAfeeArtemis!42264C845954
VBA32Hoax.Blocker
PandaTrj/CI.A
TencentWin32.Trojan.Blocker.Ozic
YandexTrojan.Blocker!ajWhR4gksUA
MAXmalware (ai score=99)
eGambitUnsafe.AI_Score_99%
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASOYA

How to remove Trojan-Ransom.Win32.Blocker.gqmj?

Trojan-Ransom.Win32.Blocker.gqmj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment