Ransom Trojan

Trojan-Ransom.Win32.Blocker.kpii malicious file

Malware Removal

The Trojan-Ransom.Win32.Blocker.kpii is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.kpii virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Trojan-Ransom.Win32.Blocker.kpii?


File Info:

crc32: 48CDED57
md5: 167cef1def04dbd1932da0aaedb95de1
name: 167CEF1DEF04DBD1932DA0AAEDB95DE1.mlw
sha1: 0aea471a1686097f4a03ebb2e200a19c8bab920d
sha256: 80f8cb749b5936f4585ca115505c38ccf46a989e257367be524b5f56f10bb1f9
sha512: 0eca9d905cecc14244e427e32ed368925908e0e688d387c0dcd0644f53860667b4159054b0665350609aa9d3177e2572684deaf8aae94e0b5b9ecd6581599599
ssdeep: 6144:TCY0jhjl+k3MMIMTkfMEUZIvsyBWJ4b4lcwMoDcckF:T05+kRjkPqIvsyB7b4WAcF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Blocker.kpii also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.Winlock.3333
CynetMalicious (score: 100)
ZillyaTrojan.Yakes.Win32.13964
CrowdStrikewin/malicious_confidence_90% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/LockScreen.AGU
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.kpii
NANO-AntivirusTrojan.Win32.Yakes.xoybh
TencentWin32.Trojan.Yakes.ink
SophosMal/Generic-S
ComodoSuspicious@#156fiurzs8dm8
BitDefenderThetaGen:NN.ZelphiF.34628.sGW@aWH83hg
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Android.fh
FireEyeGeneric.mg.167cef1def04dbd1
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1117114
MicrosoftTrojan:Win32/Ransom.DR
McAfeePWS-Zbot.gen.bgi
PandaTrj/Pacrypt.E
RisingRansom.Genasom!8.293 (CLOUD)
YandexTrojan.DR!Li1ZSRgnEl8
IkarusTrojan.Win32.Menti
FortinetW32/Zbot.AAO!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360HEUR/QVM05.1.Malware.Gen

How to remove Trojan-Ransom.Win32.Blocker.kpii?

Trojan-Ransom.Win32.Blocker.kpii removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment