Ransom Trojan

Should I remove “Trojan-Ransom.Win32.Blocker.jtza”?

Malware Removal

The Trojan-Ransom.Win32.Blocker.jtza is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.jtza virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Creates a copy of itself
  • Appends a known CryptFile2 ransomware file extension to files that have been encrypted
  • Creates a known CryptFile2 ransomware decryption instruction / key file.

How to determine Trojan-Ransom.Win32.Blocker.jtza?


File Info:

crc32: 7B92A998
md5: 26b90d1409d50904a2103396592f100c
name: 26B90D1409D50904A2103396592F100C.mlw
sha1: 9c6d7d4fcd06256a272898b38bd4c1fbfcdea4a3
sha256: bf7277a52acc0c600aaf96281db2553ed24d3dface9d9e22de3764de7037fb5b
sha512: fc69e4811eac5c89ed25d9a0ca50d1525d44363a49107e56d3699c39bde887a14edb163c6dc819555cafcd38a8dc04622d2071d3816e8835327702a733f820f5
ssdeep: 768:vKBoGzMkhAnO7PB9e5uXWkqnqje3aHxyEKxDdw6lCcGDSSx7D:3GYpIBFWFnkjxGzplVGDS
type: MS-DOS executable, MZ for MS-DOS

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Blocker.jtza also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Blocker.j!c
DrWebTrojan.DownLoader22.55095
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Dreidel.cmqax85EZ@di
CylanceUnsafe
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.409d50
SymantecRansom.CryptXXX
ESET-NOD32a variant of Win32/Kryptik.FHAQ
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.Blocker.jtza
BitDefenderGen:Heur.Mint.Dreidel.cmqax85EZ@di
NANO-AntivirusTrojan.Win32.Blocker.eiohts
MicroWorld-eScanGen:Heur.Mint.Dreidel.cmqax85EZ@di
TencentWin32.Trojan.Blocker.Hsiz
Ad-AwareGen:Heur.Mint.Dreidel.cmqax85EZ@di
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34170.cmqaa85EZ@di
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.pc
FireEyeGeneric.mg.26b90d1409d50904
EmsisoftGen:Heur.Mint.Dreidel.cmqax85EZ@di (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Snocry.cm
eGambitUnsafe.AI_Score_93%
Antiy-AVLTrojan/Generic.ASMalwS.1B8A961
MicrosoftRansom:Win32/Genasom
ZoneAlarmTrojan-Ransom.Win32.Blocker.jtza
GDataGen:Heur.Mint.Dreidel.cmqax85EZ@di
Acronissuspicious
McAfeeArtemis!26B90D1409D5
MAXmalware (ai score=100)
VBA32Trojan-Ransom.Blocker
PandaTrj/CI.A
YandexPacked/MPress
IkarusTrojan-Dropper.Win32.Dorifel
FortinetW32/Kryptik.FHAQ!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Blocker.jtza?

Trojan-Ransom.Win32.Blocker.jtza removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment