Ransom Trojan

What is “Trojan-Ransom.Win32.Blocker.krll”?

Malware Removal

The Trojan-Ransom.Win32.Blocker.krll is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.krll virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Starts servers listening on 0.0.0.0:12607, 0.0.0.0:21223
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to identify installed AV products by registry key
  • Anomalous binary characteristics

Related domains:

k.modakenchina.com
s.modakenchina.com

How to determine Trojan-Ransom.Win32.Blocker.krll?


File Info:

crc32: 54EEF21F
md5: 554e7451b1244e6c1c0b58f144d5c59a
name: 554E7451B1244E6C1C0B58F144D5C59A.mlw
sha1: 76679ea81fbd373d1445984c5c0201382a17f08f
sha256: 01e26266c463baefa436036687703fb96abf76f65c2e31fb0bffe0d3957bd86c
sha512: 2c69ac9fc2a09777e9efc5ea20cef970b983104af2c13b0d4c47c5bd01f89fab3662386436c4d795e65a4da808120e53a7b2e2515a8f666ef6a41059dfa129bc
ssdeep: 6144:GpqmyLhLx05Jf8Qlh8LTImy6H9Kb/JDw:GkwOQlhoTKQ9W
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Blocker.krll also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053305e1 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop7.63535
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.ZZ5
ALYacTrojan.BRMon.Gen.3
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.39650
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Bunitu.ali1000105
K7GWTrojan ( 0053305e1 )
Cybereasonmalicious.1b1244
CyrenW32/S-60546053!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GDFO
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.krll
BitDefenderTrojan.BRMon.Gen.3
NANO-AntivirusTrojan.Win32.GandCrypt.eybtoj
ViRobotTrojan.Win32.U.Gandcrab.315904
MicroWorld-eScanTrojan.BRMon.Gen.3
TencentMalware.Win32.Gencirc.114cdd30
Ad-AwareTrojan.BRMon.Gen.3
SophosMal/Generic-S + Mal/GandCrab-B
ComodoTrojWare.Win32.Ransom.GandCrypt.C@7ivv6t
BitDefenderThetaGen:NN.ZexaF.34058.nuW@ae49!s
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPGANDCRAB.SMG2
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.554e7451b1244e6c
EmsisoftTrojan.BRMon.Gen.3 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Blocker.iop
AviraHEUR/AGEN.1126869
eGambitUnsafe.AI_Score_85%
Antiy-AVLTrojan/Generic.ASMalwS.247E15A
MicrosoftRansom:Win32/Gandcrab.SF!MTB
ArcabitTrojan.BRMon.Gen.3
SUPERAntiSpywareTrojan.Agent/Gen-Suloc
GDataTrojan.BRMon.Gen.3
AhnLab-V3Trojan/Win32.Blocker.C2410904
Acronissuspicious
McAfeeGenericRXEB-NI!554E7451B124
MAXmalware (ai score=98)
VBA32BScope.Trojan.MulDrop
MalwarebytesMalware.AI.1866875762
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPGANDCRAB.SMG2
RisingMalware.Obscure!1.A3BB (CLASSIC)
YandexTrojan.GenAsa!a+TFcR+Fjz0
IkarusTrojan-Dropper.Win32.Danabot
MaxSecureRansomeware.CRAB.gen
FortinetW32/Kryptik.HCUD!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwoCEpsA

How to remove Trojan-Ransom.Win32.Blocker.krll?

Trojan-Ransom.Win32.Blocker.krll removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment