Ransom Trojan

Trojan-Ransom.Win32.Blocker.hqlo removal guide

Malware Removal

The Trojan-Ransom.Win32.Blocker.hqlo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.hqlo virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Ransom.Win32.Blocker.hqlo?


File Info:

crc32: 842817C7
md5: 61381610e76266423ace96670de45dc0
name: 61381610E76266423ACE96670DE45DC0.mlw
sha1: 54c4e3806e7a8d67b4992915e2f099c1ed7d8a74
sha256: c4fb589ef2489b268de6819fc9e78874da81d0132f37919730b2919fb9bfcaf0
sha512: ea9a77b6afc8aad8792827040951e0453383c1e9249e3f6475984e61cb71f46c584cf4992e3a53d1cb7cdcdf17af4a954dd773e6fb80de98202fd513477bf386
ssdeep: 12288:dv1jZOimsQK1b+b85iw7UfvrFS0AcKJVfNlAfEBWiXZe16qQqGAx:dv1kibB1b55iw7U7kWKJVNlAMciXoCA
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.1.21.03
ProductName:
ProductVersion: 1.1.21.03
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Blocker.hqlo also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanTrojan.GenericKD.2709598
McAfeeArtemis!61381610E762
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Blocker.j!c
SangforTrojan.Win32.Agent.nil
K7AntiVirusTrojan ( 004c2b1c1 )
BitDefenderTrojan.GenericKD.2709598
K7GWTrojan ( 004c2b1c1 )
ArcabitTrojan.Generic.D29585E
SymantecTrojan.Dunihidrop
ESET-NOD32VBS/Agent.NDW
TrendMicro-HouseCallBKDR_BLADABINDI.YYQB
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.hqlo
AlibabaRansom:Win32/Blocker.8d13ad0d
NANO-AntivirusTrojan.Win32.Blocker.dwsirc
RisingMalware.FakeXLS@CV!1.9C3D (CLOUD)
Ad-AwareTrojan.GenericKD.2709598
EmsisoftTrojan.GenericKD.2709598 (B)
ComodoMalware@#2e1d2o3dudyju
F-SecureTrojan.TR/VB.Agent.571904
ZillyaTrojan.Blocker.Win32.31331
TrendMicroBKDR_BLADABINDI.YYQB
McAfee-GW-EditionBehavesLike.Win32.Injector.hc
FireEyeGeneric.mg.61381610e7626642
SophosMal/Generic-S
IkarusWorm.VBS.Agent
JiangminTrojan.Blocker.bph
MaxSecureTrojan.Malware.300983.susgen
AviraTR/VB.Agent.571904
MAXmalware (ai score=99)
Antiy-AVLTrojan[Ransom]/Win32.Blocker
KingsoftWin32.Heur.KVM007.a.(kcloud)
MicrosoftTrojan:Win32/Vigorf.A
ZoneAlarmTrojan-Ransom.Win32.Blocker.hqlo
GDataTrojan.GenericKD.2709598
CynetMalicious (score: 100)
VBA32Hoax.Blocker
ALYacTrojan.GenericKD.2709598
MalwarebytesMalware.AI.3657673518
PandaGeneric Suspicious
APEXMalicious
TencentWin32.Trojan.Blocker.Wlfk
YandexTrojan.Blocker!3j8B7KULzII
eGambitGeneric.Malware
FortinetW32/Blocker.HQLO!tr
AVGWin32:Malware-gen
Cybereasonmalicious.0e7626
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASOoA

How to remove Trojan-Ransom.Win32.Blocker.hqlo?

Trojan-Ransom.Win32.Blocker.hqlo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment