Ransom Trojan

What is “Trojan-Ransom.Win32.Blocker.kwsl”?

Malware Removal

The Trojan-Ransom.Win32.Blocker.kwsl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.kwsl virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs an hook procedure to monitor for mouse events
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to disable UAC

Related domains:

www.filmgetir.com
ww1.filmgetir.com
www.filmver.com
www.pornokan.com

How to determine Trojan-Ransom.Win32.Blocker.kwsl?


File Info:

crc32: 18C95AFE
md5: b1287f6f82640c043246f4d8dcc57375
name: B1287F6F82640C043246F4D8DCC57375.mlw
sha1: dfbe3ad87b0ce02beeee2c9d2444043be2d18d38
sha256: 3cde4e3dd88722a74fa019384892cf58760b18abde02f6d20f39b1ef3746920a
sha512: 75e85f1ae65236b19a01a3760b95c9268ce3c22d851ae2b64767b37310eed9ea910144466e127151d96ccd6e322a6e7d140d98e0769a840f6f01b6183d4a30bd
ssdeep: 12288:yNIQAPGsAqY9IMVYd38sJdpQHGklY8Kf64zWdz83NEDE:fPGSY91VwNJcmyq64zLuDE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Apple Inc.
FileDescription: Apple Inc. 9.1.2 Installation
FileVersion: 9.1.2
Comments:
CompanyName: Apple Inc.
Translation: 0x0409 0x04e4

Trojan-Ransom.Win32.Blocker.kwsl also known as:

K7AntiVirusTrojan ( 004c2c031 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.DownLoader13.27832
ALYacGen:Variant.Ransom.1994
CylanceUnsafe
SangforTrojan.Win32.Kilim.U
K7GWTrojan ( 004c2c031 )
Cybereasonmalicious.f82640
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of JS/ExtenBro.FBook.FW
APEXMalicious
AvastWin32:Downloader-VYF [Trj]
CynetMalicious (score: 99)
KasperskyTrojan-Ransom.Win32.Blocker.kwsl
BitDefenderGen:Variant.Ransom.1994
NANO-AntivirusTrojan.Win32.Dwn.dsqiib
MicroWorld-eScanGen:Variant.Ransom.1994
TencentWin32.Trojan.Generic.Pboq
Ad-AwareGen:Variant.Ransom.1994
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34050.Pq3@amg8Qifi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_BPUSH.SM
McAfee-GW-EditionBehavesLike.Win32.Dropper.jh
FireEyeGeneric.mg.b1287f6f82640c04
EmsisoftGen:Variant.Ransom.1994 (B)
JiangminTrojan/Generic.bdwtj
WebrootW32.Rogue.Gen
AviraTR/Agent.684062
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Kilim.U
SUPERAntiSpywareTrojan.Agent/Gen-RansomBlocker
GDataGen:Variant.Ransom.1994
AhnLab-V3Trojan/Win32.Blocker.C742060
McAfeeArtemis!B1287F6F8264
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Blocker
MalwarebytesTrojan.KBayi.FLA
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_BPUSH.SM
RisingTrojan.Generic@ML.91 (RDML:Tmb3H3UMQflKLDIM2HBuFQ)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic!tr
AVGWin32:Downloader-VYF [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASOQA

How to remove Trojan-Ransom.Win32.Blocker.kwsl?

Trojan-Ransom.Win32.Blocker.kwsl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment