Ransom Trojan

Trojan-Ransom.Win32.Blocker.jzqx (file analysis)

Malware Removal

The Trojan-Ransom.Win32.Blocker.jzqx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.jzqx virus can do?

  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Ransom.Win32.Blocker.jzqx?


File Info:

crc32: 49F40C1E
md5: d3cb80f21debff754ae6f3293216f215
name: D3CB80F21DEBFF754AE6F3293216F215.mlw
sha1: 9cc63e8f1449dc2267860e0ee527adb9add3f16f
sha256: 2d227b39810ddcc00aab9f0fea59b41fbc529f2411b22eeb676636c4cd6faa7b
sha512: 63313fed4638cf8299b151e33bd876a1493a37556d70c132582dbf14013e040637e4d7401f0d914aa9fe250a4ef2a9199ebed291a0e195d32383a3f41ed6ea82
ssdeep: 3072:WZEPyYc6x25b/56CX3Sw5j6yEcWtfgmMW62aW62KysW62aW62Ky8SMW62aW62KyG:IE65nR6CB6BcWt4me1alom6CS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Blocker.jzqx also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004f700b1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.11790
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Amnesia.B
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 004f700b1 )
Cybereasonmalicious.21debf
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.FS
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Scarab-6336012-1
KasperskyTrojan-Ransom.Win32.Blocker.jzqx
BitDefenderTrojan.Ransom.Amnesia.B
NANO-AntivirusTrojan.Win32.GZkGW.enykjz
MicroWorld-eScanTrojan.Ransom.Amnesia.B
TencentWin32.Trojan.Raas.Auto
Ad-AwareTrojan.Ransom.Amnesia.B
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
BitDefenderThetaAI:Packer.F85BDC0220
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_Purge
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
FireEyeGeneric.mg.d3cb80f21debff75
EmsisoftTrojan.Ransom.Amnesia.B (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Heur2.GZ.kGW@baPgXUh
AviraTR/Downloader.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.1FF6E3D
MicrosoftRansom:Win32/Kitoles.A
ArcabitTrojan.Ransom.Amnesia.B
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmTrojan-Ransom.Win32.Blocker.jzqx
GDataTrojan.Ransom.Amnesia.B
AhnLab-V3Worm/Win32.RL_AutoRun.R331396
Acronissuspicious
McAfeeRansom-Amnesia!D3CB80F21DEB
MAXmalware (ai score=100)
VBA32Hoax.Blocker
MalwarebytesMalware.AI.933439735
PandaTrj/CI.A
TrendMicro-HouseCallMal_Purge
RisingTrojan.Generic@ML.98 (RDML:XU1A+0wHiwpTF7T9E7FRBQ)
YandexTrojan.GenAsa!LOo2iqBLZJ0
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Filecoder.FS!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Blocker.jzqx?

Trojan-Ransom.Win32.Blocker.jzqx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment