Ransom Trojan

Trojan-Ransom.Win32.Blocker.kkui removal tips

Malware Removal

The Trojan-Ransom.Win32.Blocker.kkui is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.kkui virus can do?

  • Network activity detected but not expressed in API logs

How to determine Trojan-Ransom.Win32.Blocker.kkui?


File Info:

crc32: 0796ECF8
md5: 6c20ce89021e3f8a8fe49b0ad1b17d44
name: 6C20CE89021E3F8A8FE49B0AD1B17D44.mlw
sha1: 8a2a74d0fa19b630278ec805b2854cbda90a18df
sha256: 14d45b450b3cf2c019667581a3a9e7b824e09122b7f6107f56b16126bbc756e0
sha512: d2d3d4ac5fa910513e2ee17454d98bd936af076ec639b0e709b4e35c4740a154fd8f0c5431482598afd37b1d222132ce1700fb4528697416dff705338f1df6fc
ssdeep: 3072:mjTzw/1UMWwQVAKfM33JTElRGpSD8xAot+1D:GTz21UKx3ZTeHL
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: 750185c8-a3af-435d-8d39-cc836380f4b8
Assembly Version: 7.4.0.0
InternalName: WindowsApplication1.exe
FileVersion: 7.4.0.0
CompanyName: 750185c8-a3af-435d-8d39-cc836380f4b8750185c8-a3af-435d-8d39-cc836380f4b8
LegalTrademarks: 750185c8-a3af-435d-8d39-cc836380f4b8
Comments: 750185c8-a3af-435d-8d39-cc836380f4b8
ProductName: 750185c8-a3af-435d-8d39-cc836380f4b8750185c8-a3af-435d-8d39-cc836380f4b8
ProductVersion: 7.4.0.0
FileDescription: 750185c8-a3af-435d-8d39-cc836380f4b8
OriginalFilename: WindowsApplication1.exe

Trojan-Ransom.Win32.Blocker.kkui also known as:

K7AntiVirusTrojan ( 005073db1 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop6.41614
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.12552118
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Blocker.bac62b2f
K7GWTrojan ( 005073db1 )
Cybereasonmalicious.9021e3
SymantecBackdoor.Ratenjay
ESET-NOD32a variant of MSIL/Kryptik.HGK
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.kkui
BitDefenderTrojan.GenericKD.12552118
NANO-AntivirusTrojan.Win32.Blocker.euwanf
MicroWorld-eScanTrojan.GenericKD.12552118
TencentWin32.Trojan.Blocker.Wozo
Ad-AwareTrojan.GenericKD.12552118
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Bladabindi.csjux
BitDefenderThetaGen:NN.ZemsilF.34142.lm0@aGXSzY
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.6c20ce89021e3f8a
EmsisoftTrojan.GenericKD.12552118 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.htx
AviraTR/AD.Bladabindi.csjux
Antiy-AVLTrojan[Ransom]/Win32.Blocker
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Generic.DBF87B6
ZoneAlarmTrojan-Ransom.Win32.Blocker.kkui
GDataTrojan.GenericKD.12552118
AhnLab-V3Backdoor/Win32.SpyGate.R217839
McAfeeArtemis!6C20CE89021E
MAXmalware (ai score=99)
VBA32Trojan-Ransom.Blocker
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
YandexTrojan.Blocker!7dZnyAZSIlk
IkarusTrojan.MSIL.CryptoObfuscator
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.HGK!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Blocker.kkui?

Trojan-Ransom.Win32.Blocker.kkui removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment