Ransom Trojan

Trojan-Ransom.Win32.Blocker.kwrr information

Malware Removal

The Trojan-Ransom.Win32.Blocker.kwrr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.kwrr virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs an hook procedure to monitor for mouse events
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to disable UAC

Related domains:

www.filmgetir.com
ww1.filmgetir.com
www.kingtr.click
www.pornokan.com

How to determine Trojan-Ransom.Win32.Blocker.kwrr?


File Info:

crc32: 096815D1
md5: bb53504afac59766eaf8d8c448182bae
name: BB53504AFAC59766EAF8D8C448182BAE.mlw
sha1: a408d22f3c7f474f5ee9edb44f250486714ded9b
sha256: ab6cd6442359c9ea8a279f89fb141c745915673706bd35f6f384cfda6b2117f7
sha512: c31e5666c596c1fb5addaff3569ccecefa5f3f4986d1d79f71077cf4c5fa0119bcdd78c0bdee44544856bbc11a33bad01bd72b453339b271e9c8b268e5781157
ssdeep: 12288:6NIQAPGsAqY9IMVYd38sJdpQHrulY8KfbZSYOMDVWM2/d+kEzO:nPGSY91VwNJcL0qbZhOgVWMVkz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Apple Inc.
FileDescription: Apple Inc. 9.1.2 Installation
FileVersion: 9.1.2
Comments:
CompanyName: Apple Inc.
Translation: 0x0409 0x04e4

Trojan-Ransom.Win32.Blocker.kwrr also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004c2c031 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader26.42335
ALYacGen:Variant.Ransom.1994
CylanceUnsafe
SangforTrojan.Win32.Symmi.frsV
K7GWTrojan ( 004c2c031 )
Cybereasonmalicious.afac59
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of JS/ExtenBro.FBook.FW
APEXMalicious
AvastWin32:Downloader-VYF [Trj]
KasperskyTrojan-Ransom.Win32.Blocker.kwrr
BitDefenderGen:Variant.Ransom.1994
NANO-AntivirusTrojan.Win32.Blocker.fbimjc
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
MicroWorld-eScanGen:Variant.Ransom.1994
Ad-AwareGen:Variant.Ransom.1994
SophosMal/Generic-S
ComodoMalware@#36knjx08sbq22
BitDefenderThetaGen:NN.ZexaF.34744.Qq3@amjhi2ci
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_BPUSH.SM
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.bb53504afac59766
EmsisoftGen:Variant.Ransom.1994 (B)
JiangminTrojan/Blocker.mks
WebrootW32.Rogue.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Kilim.U
ArcabitTrojan.Ransom.D7CA
AegisLabTrojan.Win32.Blocker.j!c
GDataGen:Variant.Ransom.1994
AhnLab-V3Trojan/Win32.Blocker.C742060
McAfeeArtemis!BB53504AFAC5
MAXmalware (ai score=88)
VBA32BScope.TrojanRansom.Blocker
MalwarebytesTrojan.KBayi.FLA
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_BPUSH.SM
RisingTrojan.Generic@ML.93 (RDMK:aHl5GFqAE5a7TmZcxMlZWg)
YandexTrojan.Blocker!QGoTd2ToN7Q
IkarusTrojan.Win32.AHK
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Blocker.GYMH!tr
AVGWin32:Downloader-VYF [Trj]
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Blocker.kwrr?

Trojan-Ransom.Win32.Blocker.kwrr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment