Ransom Trojan

Should I remove “Trojan-Ransom.Win32.Blocker.ihhb”?

Malware Removal

The Trojan-Ransom.Win32.Blocker.ihhb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.ihhb virus can do?

  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Indonesian
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Attempts to block SafeBoot use by removing registry keys

Related domains:

edgedl.me.gvt1.com
update.googleapis.com

How to determine Trojan-Ransom.Win32.Blocker.ihhb?


File Info:

crc32: 1E69E051
md5: 11dc49ba65310caa555fd927ec448e69
name: 11DC49BA65310CAA555FD927EC448E69.mlw
sha1: 75c1ce88a75be4193f06193b414caf556b37cc93
sha256: 3178723a98673d3e6ea743fb03699df145e2a99aeeb19cc13799dcb617e5487b
sha512: 7c92457f76c378fe6d35c13d271b73feabfad1e661794791a5002898067f0af052198dd43feea8edd8c8ab0db0b1eea82ea4d45a0f7d5e4a1a4841294886d4ba
ssdeep: 12288:S3/02a6zwPNVG+WqhWhWtF33833PBKKK2KKKQKKZKKeHHHTHHH8///////FN:m82aaQNJxW+33833PBKKK2KKKQKKZKK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2001-2004 CaesarSOFT Inc.
InternalName:
FileVersion: 6.0.4.1264
CompanyName: CaesarSOFT
LegalTrademarks:
Comments: visit http://www.caesarsoft.com
ProductName: CyberBilling
ProductVersion: XP
FileDescription: CyberBilling Client
OriginalFilename: CyberClient
Translation: 0x0421 0x04e4

Trojan-Ransom.Win32.Blocker.ihhb also known as:

CynetMalicious (score: 100)
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.37224
SangforSuspicious.Win32.Save.a
AlibabaRansom:Win32/Blocker.5bc428bc
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMetagen [PUP]
ClamAVWin.Trojan.6712272-1
KasperskyTrojan-Ransom.Win32.Blocker.ihhb
NANO-AntivirusTrojan.Win32.Blocker.fbnxet
SophosMal/Generic-S
ComodoSuspicious@#4zy3ozxsz3ry
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.hh
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Generic.ASMalwS.8616A4
KingsoftWin32.Troj.Generic.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeGenericRXBS-PE!11DC49BA6531
IkarusTrojan.ATRAPS
MaxSecureTrojan.Malware.2817002.susgen
AVGFileRepMetagen [PUP]
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Blocker.ihhb?

Trojan-Ransom.Win32.Blocker.ihhb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment