Ransom Trojan

Trojan-Ransom.Win32.Blocker.jufk removal instruction

Malware Removal

The Trojan-Ransom.Win32.Blocker.jufk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.jufk virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to disable UAC
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Ransom.Win32.Blocker.jufk?


File Info:

crc32: 5CE3487A
md5: 985ae2fa05f166886140c2733df06bc7
name: 985AE2FA05F166886140C2733DF06BC7.mlw
sha1: 9f7e7eed20c341ddb7856e10525870ddd308d654
sha256: 8f2a78b4b0b88709ec00a8e115b6cec125638bc67ba4d50b02bf4a6c1e524c50
sha512: 8de7bbed37db6b2122dd100b783f737f0dd6b943acfb910c158c5c8edc9abfc051d3c382d4f9872eae48c6d4be70ea29a7898fe97c5bd44bdf6437b128dc7685
ssdeep: 24576:4twDXHYNXjSNuLxVA0tkxf99wwsJrscPFaL2wdz68J5Nu60Xav:QweXsIu3xEJrsxndz6W5A64av
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: ddd.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: ddd.exe

Trojan-Ransom.Win32.Blocker.jufk also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e39b1 )
Elasticmalicious (high confidence)
ClamAVWin.Malware.Quasar-9785200-0
MalwarebytesMalware.Heuristic.1003
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/Blocker.056bb12e
K7GWTrojan ( 0055e39b1 )
Cybereasonmalicious.a05f16
BitDefenderThetaAI:Packer.9EB9E32713
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.EnigmaProtector.J suspicious
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.jufk
BitDefenderGen:Packer.Enigma.1
NANO-AntivirusTrojan.Win32.Blocker.ejbzpe
MicroWorld-eScanGen:Packer.Enigma.1
TencentWin32.Trojan.Blocker.Htly
Ad-AwareGen:Packer.Enigma.1
SophosML/PE-A
ComodoMalware@#1gz6p4xftk16
DrWebTrojan.Siggen3.53454
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.985ae2fa05f16688
EmsisoftGen:Packer.Enigma.1 (B)
AviraHEUR/AGEN.1128071
eGambitUnsafe.AI_Score_100%
MicrosoftWorm:MSIL/Necast.H
AegisLabTrojan.Win32.Blocker.j!c
GDataGen:Packer.Enigma.1
TACHYONTrojan/W32.Agent.1132032.W
Acronissuspicious
McAfeeArtemis!985AE2FA05F1
MAXmalware (ai score=82)
VBA32TScope.Trojan.MSIL
PandaTrj/Genetic.gen
RisingMalware.Heuristic!ET (C64:YzY0OiVA0Mxe8ElF)
YandexTrojan.Blocker!Cijw4a+9Xu4
SentinelOneStatic AI – Suspicious PE
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASOgA

How to remove Trojan-Ransom.Win32.Blocker.jufk?

Trojan-Ransom.Win32.Blocker.jufk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment