Ransom Trojan

Trojan-Ransom.Win32.Blocker.kqqs malicious file

Malware Removal

The Trojan-Ransom.Win32.Blocker.kqqs is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.kqqs virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

googleads.publicvm.com

How to determine Trojan-Ransom.Win32.Blocker.kqqs?


File Info:

crc32: 97DB6B4C
md5: 43f5fa4d5cfd5dd36bd1d654fd921b1b
name: 43F5FA4D5CFD5DD36BD1D654FD921B1B.mlw
sha1: 98f710fddda160179df9d1c6bd5a95caf2349836
sha256: 9f6828fee36982f2c13e82285abbcab76cbc80e1c0cf0e7d29f4da2adba0e34d
sha512: 6ee188054100fd7ee471d7655dd367721b73b2a3bfdc3aa3585eaa3970f69b88fa4cdfc6a6990d4ea67e0e30447d65330787f0628895d94167cdf7152fef9f85
ssdeep: 49152:jJZoQrbTFZY1ialAHvv0GLl5+/+ghoIpq9+iXl:jtrbTA1kvjLl5APhon9hl
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

Trojan-Ransom.Win32.Blocker.kqqs also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004590191 )
Elasticmalicious (high confidence)
DrWebBackDoor.IRC.Bot.3591
ClamAVWin.Trojan.Autoit-6922942-0
ALYacAIT:Trojan.Nymeria.2809
MalwarebytesMalware.AI.3624907405
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderTrojan.GenericKD.41864804
K7GWTrojan ( 004590191 )
CyrenW32/Trojan.ODRX-0142
SymantecTrojan.Gen.2
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.kqqs
AlibabaRansom:Win32/Blocker.ff9d7f29
NANO-AntivirusTrojan.Win32.Verecno.exvjgj
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
MicroWorld-eScanTrojan.GenericKD.41864804
Ad-AwareTrojan.GenericKD.41864804
SophosMal/Generic-S
BitDefenderThetaAI:Packer.5642CD7B16
VIPRETrojan.Win32.Generic!BT
TrendMicroWorm.Win32.OTORUN.NKLSFR
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
FireEyeGeneric.mg.43f5fa4d5cfd5dd3
EmsisoftTrojan.GenericKD.41864804 (B)
AviraHEUR/AGEN.1110325
eGambitUnsafe.AI_Score_95%
MicrosoftTrojan:Win32/Autdis.A
ArcabitAIT:Trojan.Nymeria.DAF9
AegisLabTrojan.Win32.Genome.m9J3
ZoneAlarmTrojan-Ransom.Win32.Blocker.kqqs
GDataAIT:Trojan.Nymeria.2809 (3x)
AhnLab-V3Trojan/Win32.Blocker.C2375220
McAfeeArtemis!43F5FA4D5CFD
MAXmalware (ai score=99)
TrendMicro-HouseCallWorm.Win32.OTORUN.NKLSFR
IkarusTrojan-Spy.FormBook
MaxSecureTrojan.Autoit.AZA
PandaTrj/CI.A

How to remove Trojan-Ransom.Win32.Blocker.kqqs?

Trojan-Ransom.Win32.Blocker.kqqs removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment