Ransom Trojan

Trojan-Ransom.Win32.Blocker.jjle removal tips

Malware Removal

The Trojan-Ransom.Win32.Blocker.jjle is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.jjle virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
theexecuter.sytes.net

How to determine Trojan-Ransom.Win32.Blocker.jjle?


File Info:

crc32: 095EEBFA
md5: 517277c541641d24a73805a068767c03
name: 517277C541641D24A73805A068767C03.mlw
sha1: bf06df5b66508ea7ca8df505d31b6f78680f3e71
sha256: 3436d7b4bbfba62c3bc952185b5eec11d957ca26a2f8098ae31e608599dd4df5
sha512: 5171f5387a0c1a7d63ce078c91718151f3e074b4b6ecac96c155fecc8b6c018e641340244368c872a6ae23b2a2bd8a65c428ef3b5445bf67506011824a54df51
ssdeep: 768:+Et7r20XmINBCbeY56QBUuGZW0CJVN/yT5kgzPhGIcB9AK:+IrrgbnjBrCCJOT5kgzsvB9AK
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Blocker.jjle also known as:

K7AntiVirusTrojan ( 005731771 )
LionicTrojan.Win32.Generic.lXyg
DrWebTrojan.DownLoad3.12110
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Titirez.cGW@bmFaprg
CylanceUnsafe
ZillyaTrojan.Injector.Win32.155583
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 005731771 )
Cybereasonmalicious.541641
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.Blocker.jjle
BitDefenderGen:Heur.Mint.Titirez.cGW@bmFaprg
NANO-AntivirusTrojan.Win32.DownLoad3.bbxdng
MicroWorld-eScanGen:Heur.Mint.Titirez.cGW@bmFaprg
TencentWin32.Trojan.Genome.Stty
Ad-AwareGen:Heur.Mint.Titirez.cGW@bmFaprg
SophosMal/Generic-S
ComodoMalware@#16pnbnwkn9q6g
BitDefenderThetaGen:NN.ZexaF.34110.cGW@amFaprg
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.nc
FireEyeGeneric.mg.517277c541641d24
EmsisoftGen:Heur.Mint.Titirez.cGW@bmFaprg (B)
JiangminTrojan/Genome.clfr
WebrootW32.Trojan.Gen
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.19CE674
KingsoftWin32.Troj.Genome.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Heur.Mint.Titirez.cGW@bmFaprg
TACHYONTrojan/W32.Genome.35840.O
McAfeeArtemis!517277C54164
MAXmalware (ai score=83)
VBA32BScope.Trojan.Scarsi
PandaTrj/CI.A
YandexTrojan.Injector!NiqG/oXfv0E
IkarusWin32.SuspectCrc
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Dx.BGJ4!tr
AVGWin32:Trojan-gen

How to remove Trojan-Ransom.Win32.Blocker.jjle?

Trojan-Ransom.Win32.Blocker.jjle removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment