Ransom Trojan

Trojan-Ransom.Win32.Blocker.krjw removal instruction

Malware Removal

The Trojan-Ransom.Win32.Blocker.krjw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.krjw virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Starts servers listening on 0.0.0.0:14711, 0.0.0.0:38298
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to identify installed AV products by registry key
  • Anomalous binary characteristics

Related domains:

k.modakenchina.com

How to determine Trojan-Ransom.Win32.Blocker.krjw?


File Info:

crc32: 2AF99242
md5: 12e98ba0a350c7a756f763aa2f538fad
name: 12E98BA0A350C7A756F763AA2F538FAD.mlw
sha1: 4daffaa2a6649291be9321e221e1a678d1ba4c0a
sha256: 5ac9b3964054b394450e4117f148a0f0ef51b846df54b7c0fd3e52b727ea7715
sha512: 8262abfba60850b9cbc0b8e0e31566ba068ca6470d332a38c263fa2700c047fa96fd5931fd3e2c2ef0c6f63ee57a4d55a14c012880b233d07b7cbcd9b6de1cd5
ssdeep: 6144:J1a0Hmxvu5uBXkwt9ALUsDXb97ZMvTV7qA:Ji/Owt9MUE9A
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Blocker.krjw also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053305e1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24384
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.ZZ5
ALYacTrojan.BRMon.Gen.3
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.39679
SangforVirus.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0053305e1 )
Cybereasonmalicious.0a350c
CyrenW32/S-60546053!Eldorado
ESET-NOD32a variant of Win32/Kryptik.GDFO
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Gandcrab-9892248-0
KasperskyTrojan-Ransom.Win32.Blocker.krjw
BitDefenderTrojan.BRMon.Gen.3
NANO-AntivirusTrojan.Win32.GenKryptik.eybjby
MicroWorld-eScanTrojan.BRMon.Gen.3
TencentWin32.Trojan.Blocker.Dzan
Ad-AwareTrojan.BRMon.Gen.3
SophosMal/Generic-R + Mal/GandCrab-B
ComodoTrojWare.Win32.Ransom.GandCrypt.C@7ivv6t
F-SecureHeuristic.HEUR/AGEN.1126869
BitDefenderThetaGen:NN.ZexaF.34170.nuW@aGS3x4m
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPGANDCRAB.SMG2
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.12e98ba0a350c7a7
EmsisoftTrojan.BRMon.Gen.3 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Crusis.sn
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1126869
Antiy-AVLTrojan[Ransom]/Win32.Blocker
MicrosoftRansom:Win32/Gandcrab.SF!MTB
ArcabitTrojan.BRMon.Gen.3
ZoneAlarmTrojan-Ransom.Win32.Blocker.krjw
GDataTrojan.BRMon.Gen.3
AhnLab-V3Trojan/Win32.Blocker.C2416262
Acronissuspicious
McAfeeGenericRXEB-QH!12E98BA0A350
MAXmalware (ai score=99)
VBA32BScope.Trojan.MulDrop
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPGANDCRAB.SMG2
RisingMalware.Obscure!1.A3BB (CLASSIC)
YandexTrojan.GandCrypt!zs+7eGko/L0
IkarusTrojan-Dropper.Win32.Danabot
MaxSecureRansomeware.CRAB.gen
FortinetW32/Kryptik.HCUD!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Blocker.krjw?

Trojan-Ransom.Win32.Blocker.krjw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment