Ransom Trojan

Trojan-Ransom.Win32.Blocker.jaty removal

Malware Removal

The Trojan-Ransom.Win32.Blocker.jaty is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.jaty virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Starts servers listening on 0.0.0.0:2057
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings

How to determine Trojan-Ransom.Win32.Blocker.jaty?


File Info:

name: D1EFA4D286EBF469A582.mlw
path: /opt/CAPEv2/storage/binaries/8b321550a94c833f65d502b2471074e0cef8554fb9d4ee1f02e7130f07ce5b40
crc32: EABED6E5
md5: d1efa4d286ebf469a5820cf36461def4
sha1: 9358080adaff58a7f267d3b2fe493087271aa00e
sha256: 8b321550a94c833f65d502b2471074e0cef8554fb9d4ee1f02e7130f07ce5b40
sha512: a410a7d9c4d0fe94b9532d842a124d4d812daba4400510cbe2505a31c9ec943fd35e3593786125a2f1f91ad21b8cf0f5c48eabab39e613ec539609074b7e59b9
ssdeep: 12288:Cb5syS5Z5Z5sy/yS5Z5Z5Z5B+G5Z5Z5B+byS5Z5Z5syS5anE5Z5syS5Z5Z5Z5Z5I:Qeamez0P
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BC15024AF5EDAB61E92778F7F2CD654084B701994E042511E6AB33A2612ED33D1FC38E
sha3_384: 9dc31ca56c53f3d2c3b03e6623ed7e7beef555f258ad1a24d51de3d6607f9ca4a59ffbb78d0dc819f4db2dfb7fed4a20
ep_bytes: 60be007057018dbe00a0e8fe5783cdff
timestamp: 2008-04-02 18:32:48

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Blocker.jaty also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.KillFiles.13123
MicroWorld-eScanTrojan.Crypt.AS
FireEyeGeneric.mg.d1efa4d286ebf469
CAT-QuickHealTrojan.Toga.26592
McAfeeObfuscated-FPR!hb
CylanceUnsafe
ZillyaWorm.Socks.Win32.544
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 0003ef7f1 )
K7GWEmailWorm ( 0003ef7f1 )
Cybereasonmalicious.286ebf
BitDefenderThetaAI:Packer.E74840091B
VirITTrojan.Win32.Generic.WQH
CyrenW32/Socks.A.gen!Eldorado
SymantecTrojan.Dropper
ESET-NOD32a variant of Win32/Socks.NAJ
TrendMicro-HouseCallTROJ_SPNR.30CU14
ClamAVWin.Worm.Socks-7102088-0
KasperskyTrojan-Ransom.Win32.Blocker.jaty
BitDefenderTrojan.Crypt.AS
NANO-AntivirusTrojan.Win32.Socks.crakqx
SUPERAntiSpywareWorm.Socks
AvastWin32:Injecter-AT [Trj]
RisingRansom.Blocker!8.12A (RDMK:cmRtazpHJwoAhVIEwXKS6GWwgpEh)
SophosML/PE-A + Troj/Scrub-Gen
VIPREP2P-Worm.Win32.Socks.g (fs)
TrendMicroTROJ_SPNR.30CU14
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SentinelOneStatic AI – Malicious PE
EmsisoftTrojan.Crypt.AS (B)
IkarusWorm.Win32.Socks
JiangminTrojan.Blocker.igh
AviraTR/Drop.Agent.snu
Antiy-AVLTrojan/Generic.ASMalwS.183B23A
MicrosoftPWS:Win32/Zbot!ml
ZoneAlarmTrojan-Ransom.Win32.Blocker.jaty
GDataTrojan.Crypt.AS
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Socks.R76979
VBA32BScope.Worm.Socks.afv
ALYacTrojan.Crypt.AS
MalwarebytesMalware.AI.3417656905
APEXMalicious
TencentMalware.Win32.Gencirc.10cfe5a7
YandexWorm.Socks!kTEylFde0kc
MAXmalware (ai score=83)
FortinetW32/Generic.AC.209E!tr
AVGWin32:Injecter-AT [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan-Ransom.Win32.Blocker.jaty?

Trojan-Ransom.Win32.Blocker.jaty removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment