Ransom Trojan

What is “Trojan-Ransom.Win32.Blocker.kxsl”?

Malware Removal

The Trojan-Ransom.Win32.Blocker.kxsl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.kxsl virus can do?

  • At least one process apparently crashed during execution
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A scripting utility was executed
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Stores JavaScript or a script command in the registry, likely for persistence or configuration
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

How to determine Trojan-Ransom.Win32.Blocker.kxsl?


File Info:

crc32: F705ECEE
md5: d1c3713a33b5cf6177f9f6f800a85eca
name: D1C3713A33B5CF6177F9F6F800A85ECA.mlw
sha1: 93e54fb8b2c1af6f1fbd6fb4ea2bc0c7dec5adc7
sha256: b04b4f1f1103c518041b1369f089508b5c7bae35ce10f30ca76796491711410d
sha512: 3d8138781f7279d89a00c777dc34b47f2a9eaa64fddae887c735d6f5e5e00be3ca1fc886c3c4121e8245860cd48307c9c5d91ecdd5c00058718f24f3c806e20c
ssdeep: 12288:kDoqvQeE0fxxU79bbdbLwZUOtrRebxMJxr+GKu3YhejiUan6oe+X6mhFqdxjsK8:fqTfxxUXbL4YfUan6B+Kmh258n5Kc2X
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.1.21.03
ProductName:
ProductVersion: 1.1.21.03
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Blocker.kxsl also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop8.3840
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.30492646
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.71138
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 0052964f1 )
K7AntiVirusTrojan ( 0052964f1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32VBS/Agent.NDW
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.Blocker.kxsl
BitDefenderTrojan.GenericKD.30492646
NANO-AntivirusTrojan.Win32.Blocker.ezkdpx
MicroWorld-eScanTrojan.GenericKD.30492646
TencentWin32.Trojan.Blocker.Wrgd
Ad-AwareTrojan.GenericKD.30492646
SophosMal/Generic-S
ComodoMalware@#3bpmas4fkldm9
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.MultiDropper.dh
FireEyeGeneric.mg.d1c3713a33b5cf61
EmsisoftTrojan.GenericKD.30492646 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Spy.Gen2
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D1D147E6
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmTrojan-Ransom.Win32.Blocker.kxsl
GDataTrojan.GenericKD.30492646
AhnLab-V3Trojan/Win.Generic.C4509019
Acronissuspicious
McAfeeArtemis!D1C3713A33B5
MAXmalware (ai score=95)
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.90 (RDML:jfG/fWmig1EDDkt4Z+WpaQ)
IkarusWorm.VBS.Agent
FortinetW32/Blocker.KXSL!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Blocker.kxsl?

Trojan-Ransom.Win32.Blocker.kxsl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment