Ransom Trojan

About “Trojan-Ransom.Win32.Blocker.kldc” infection

Malware Removal

The Trojan-Ransom.Win32.Blocker.kldc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.kldc virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
diabs.ddns.net

How to determine Trojan-Ransom.Win32.Blocker.kldc?


File Info:

crc32: E2907B2C
md5: 78d8a0f635dd1a22ce526150f0161674
name: 78D8A0F635DD1A22CE526150F0161674.mlw
sha1: 97d342a69d68aa94b4371c55557654d3236aa589
sha256: 6259cb5edbe12d377c7a3a81c9673c95f8c107009378a78466f1bd9c589c3ab8
sha512: 473c7cb05d0be713615fe91c0dc685f23dbe2db2fdc3dea5f2dcd2e03d53a318e02ff6ae490e77efe4049979305ad6ed23692058590d75c81bcb20865eebfe62
ssdeep: 768:0bOhuZOCgvWJj8WmVGiAv7C56M2hhkTjRmiJ4QusAO:qOwYCgfBjRVJ4ZsAO
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Blocker.kldc also known as:

K7AntiVirusTrojan ( 004d65011 )
LionicTrojan.Win32.Blocker.j!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader25.59408
CynetMalicious (score: 99)
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.39212
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004d65011 )
Cybereasonmalicious.635dd1
BaiduMSIL.Backdoor.Bladabindi.a
CyrenW32/MSIL_Agent.CP.gen!Eldorado
SymantecBackdoor.Ratenjay
ESET-NOD32a variant of MSIL/Bladabindi.AH
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.kldc
BitDefenderGen:Heur.MSIL.Bladabindi.1
NANO-AntivirusTrojan.Win32.Bladabindi.euxicw
MicroWorld-eScanGen:Heur.MSIL.Bladabindi.1
TencentWin32.Trojan.Blocker.Akpk
Ad-AwareGen:Heur.MSIL.Bladabindi.1
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34050.cm0@aiatnye
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGeneric.crw
FireEyeGeneric.mg.78d8a0f635dd1a22
EmsisoftGen:Heur.MSIL.Bladabindi.1 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.229BF6F
MicrosoftBackdoor:MSIL/Bladabindi.AJ
ArcabitTrojan.MSIL.Bladabindi.1
GDataGen:Heur.MSIL.Bladabindi.1
AhnLab-V3Trojan/Win32.Bladabindi.C1930977
McAfeeGeneric.crw
MAXmalware (ai score=100)
VBA32Trojan-Ransom.Blocker
MalwarebytesBackdoor.NJRat
PandaTrj/GdSda.A
YandexTrojan.Blocker!iRCRdjAi+js
IkarusWorm.MSIL.Bladabindi
FortinetMSIL/Bladabindi.AH!worm
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.NjRAT.HgIASOkA

How to remove Trojan-Ransom.Win32.Blocker.kldc?

Trojan-Ransom.Win32.Blocker.kldc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment