Ransom Trojan

Trojan-Ransom.Win32.Blocker.ikdu removal guide

Malware Removal

The Trojan-Ransom.Win32.Blocker.ikdu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.ikdu virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system

Related domains:

rraa.linkpc.net

How to determine Trojan-Ransom.Win32.Blocker.ikdu?


File Info:

crc32: 25E55090
md5: fd5fcafff494cd2e41cd1196bd47e7f1
name: FD5FCAFFF494CD2E41CD1196BD47E7F1.mlw
sha1: a269601867b24582dd9073cdc25dc3d71e475dec
sha256: b440893d33ddf0a1e28338ca905eeb7b81760a1ebc428fc533d4a1673bbe6cdc
sha512: 4869066449bae08f1466e9f57ec0584d360c7cefc2518c38b477a1d2fbfdf21e9ffe782ec18b25dd6f2971412e69aca9b256e5fd29fdf5d428a96cb590b00413
ssdeep: 24576:HNR2zaQBt37/CZ0w1PeWnzqhqCC6+PEyB:eUsrC6aE6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.1.23.00
ProductName:
ProductVersion: 1.1.23.00
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Blocker.ikdu also known as:

K7AntiVirusTrojan ( 004f10a31 )
Elasticmalicious (high confidence)
DrWebBackDoor.IRC.Bot.3321
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Porcupine.Yq0@byOBuepig
CylanceUnsafe
SangforWorm.Win32.Generic.895400
K7GWTrojan ( 004f10a31 )
Cybereasonmalicious.ff494c
SymantecTrojan Horse
ESET-NOD32Win32/AHK.P
ZonerTrojan.Win32.73221
APEXMalicious
AvastFileRepMetagen [Malware]
ClamAVWin.Worm.Filerepmalware-6716819-0
KasperskyTrojan-Ransom.Win32.Blocker.ikdu
BitDefenderGen:Heur.Mint.Porcupine.Yq0@byOBuepig
NANO-AntivirusTrojan.Win32.Dwn.eeqofv
ViRobotTrojan.Win32.Agent.812032.I
MicroWorld-eScanGen:Heur.Mint.Porcupine.Yq0@byOBuepig
TencentWin32.Trojan.Blocker.Efbb
Ad-AwareGen:Heur.Mint.Porcupine.Yq0@byOBuepig
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
FireEyeGeneric.mg.fd5fcafff494cd2e
EmsisoftGen:Heur.Mint.Porcupine.Yq0@byOBuepig (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Deshacop.iv
AviraTR/Agent.aghb
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Dynamer!ac
SUPERAntiSpywareTrojan.Agent/Gen-VBInject
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Worm.Veanslim.D
TACHYONTrojan-Dropper/W32.FrauDrop.825856
McAfeeGeneric.afc
MAXmalware (ai score=99)
VBA32Trojan.Hotkeychick
MalwarebytesMalware.AI.573648114
PandaTrj/CI.A
RisingTrojan.Generic@ML.97 (RDMK:N1wJn3zx28Dnl0Wf+JUcFg)
YandexTrojan.Blocker!5m+xDAnou2I
IkarusTrojan.Scrami
MaxSecureTrojan.Malware.300983.susgen
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HwoCEpsA

How to remove Trojan-Ransom.Win32.Blocker.ikdu?

Trojan-Ransom.Win32.Blocker.ikdu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment