Ransom Trojan

Trojan-Ransom.Win32.Blocker.jjze (file analysis)

Malware Removal

The Trojan-Ransom.Win32.Blocker.jjze is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.jjze virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Japanese
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Installs an hook procedure to monitor for mouse events
  • Installs itself for autorun at Windows startup
  • Operates on local firewall’s policies and settings
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Ransom.Win32.Blocker.jjze?


File Info:

crc32: F0E86D78
md5: 4cc0b52ba08b7a233a2578ac5982425d
name: 4CC0B52BA08B7A233A2578AC5982425D.mlw
sha1: e66a24037ed90c7e33482de4b686e4b2da196147
sha256: 4ba908cc10a5a69f0e4b3eca21150366ddf42fb704dd23e28c04b314278fcc76
sha512: 423e19443ccefdbfb8cdbc99fa621f2628226dce6269320c7fd416f5d848cc40ba39ee35de0d6ccac33fcbd242cc62aef86df1bf46548563bf86dd8bdca693b4
ssdeep: 6144:zOqGHrUxu/3kuCnBUZzfa2i8hvH6VeISOuVMOF6FRJqDTWz0qZR62SRipWwavD1:zipWzZ8GI3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2004-2012 SHIROUZU Hiroaki All rights reserved.
InternalName: FastCopy
FileVersion: 2, 1, 1, 0
CompanyName: SHIROUZU Hiroaki
Comments: http://ipmsg.org/tools/fastcopy.html
ProductName: FastCopy
ProductVersion: 2, 1, 1, 0
FileDescription: FastCopy
OriginalFilename: FastCopy.exe
Translation: 0x0411 0x04b0

Trojan-Ransom.Win32.Blocker.jjze also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e3991 )
LionicTrojan.Win32.Windef.c!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen4.20010
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaTrojan.Windef.Win32.3656
SangforTrojan.Win32.Injector.XSV
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaRansom:Win32/Blocker.b151cb84
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.ba08b7
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.XSV
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.jjze
NANO-AntivirusTrojan.Win32.FakeAV.ebybro
TencentWin32.Trojan.Inject.Auto
SophosMal/Generic-S
ComodoMalware@#33cstyclfu41r
BitDefenderThetaGen:NN.ZevbaF.34294.Tm0@a0n5tHjG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.bz
FireEyeGeneric.mg.4cc0b52ba08b7a23
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.VB.Gen8
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.183BB05
MicrosoftVirTool:Win32/VBInject.gen!JD
AhnLab-V3Trojan/Win32.VBKrypt.R40134
McAfeeArtemis!4CC0B52BA08B
MAXmalware (ai score=100)
VBA32TrojanFakeAV.Windef
PandaTrj/GdSda.A
YandexTrojan.GenAsa!+xAw2f0C4Oc
IkarusTrojan-PWS.Win32.Zbot
FortinetW32/Injector.YMS!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Blocker.jjze?

Trojan-Ransom.Win32.Blocker.jjze removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment