Ransom Trojan

About “Trojan-Ransom.Win32.Blocker.kisa” infection

Malware Removal

The Trojan-Ransom.Win32.Blocker.kisa is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.kisa virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.Blocker.kisa?


File Info:

crc32: 7025E6F2
md5: 57c1250158aa3b659955778f3f3cc8d2
name: 57C1250158AA3B659955778F3F3CC8D2.mlw
sha1: 1307513967254ae02ee98014b5a82fcd4c644ad7
sha256: 9d568910e58f9769fc3b1d6cfc36241104a6cade58b1ac5bc14af8a87a85c59e
sha512: 1b225f953df4df22468aed20b88a8119a0e196dac4865fb89f2674cab8d55c490b81d5cd345d073199cdbed0702433b8a46ddbde22811f2c1c0b753a1f33e25a
ssdeep: 6144:BDKW1Lgbdl0TBBvjc/KAQmzBaeH9RlCBDW3mNpfq1A3PhcycO:xh1Lk70TnvjciQwePoy3mjSGPz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: 2012 TfTRLda
Assembly Version: 9.5.7.8
InternalName: 1.exe
FileVersion: 7.0.3.3
CompanyName: MZjTSGG
Comments: qVTBpKB RPX 1.3.4400.61
ProductName: gpCexdB
ProductVersion: 7.0.3.3
FileDescription: onEtwoN
OriginalFilename: 1.exe

Trojan-Ransom.Win32.Blocker.kisa also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3981 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.30872291
CylanceUnsafe
SangforTrojan.Win32.ClipBanker.mt
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0055e3981 )
Cybereasonmalicious.158aa3
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.JB
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.kisa
BitDefenderTrojan.GenericKD.30872291
MicroWorld-eScanTrojan.GenericKD.30872291
TencentWin32.Trojan.Blocker.Sxyf
Ad-AwareTrojan.GenericKD.30872291
SophosMal/Generic-S
ComodoMalware@#1j0lhdrgpv2g6
BitDefenderThetaGen:NN.ZexaF.34690.vq0@aaVRfih
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.57c1250158aa3b65
EmsisoftTrojan.GenericKD.30872291 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.MSIL.111257
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.152A220
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftBackdoor:Win32/Bladabindi!ml
AegisLabTrojan.Win32.Blocker.4!c
GDataTrojan.GenericKD.30872291
Acronissuspicious
McAfeeArtemis!57C1250158AA
MAXmalware (ai score=97)
VBA32TrojanRansom.Blocker
MalwarebytesMachineLearning/Anomalous.95%
PandaTrj/CI.A
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.Kryptik!fUEhboXfkz8
IkarusTrojan.MSIL.Crypt
FortinetMSIL/Kryptik.JB!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Blocker.kisa?

Trojan-Ransom.Win32.Blocker.kisa removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment