Ransom Trojan

How to remove “Trojan-Ransom.Win32.Blocker.ldfa”?

Malware Removal

The Trojan-Ransom.Win32.Blocker.ldfa is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.ldfa virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

How to determine Trojan-Ransom.Win32.Blocker.ldfa?


File Info:

crc32: 0C4FFA72
md5: ce482185878a7a9320936fb3e3c42b0c
name: CE482185878A7A9320936FB3E3C42B0C.mlw
sha1: bd6547b2fc97c8f7af475fd89602be12ed95ffa1
sha256: c522cded60b63b5e7e35d9b9135fbeed5dcf3f503824ec8ba847e4607e32fad3
sha512: 63f14b81044ccb5ab495c237c80289f727e72ea29d04c5b8ce2629a369a4dd5c769da7830f42d5b3e720649fc7be0a6f7961aabd9b77178b1d958f6a3a1d4860
ssdeep: 12288:4rNFmY/ofvrI2LFmyTPdPGbKslcuZjB1BhqMRT:Mb/ofvM2DTPV3slrZjBtdRT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: HandBrake Copyright xa9. All rights reserved.
InternalName: Database
FileVersion: 7.2.4.7
CompanyName: HandBrake
ProductName: Database
Languages: English
ProductVersion: 7.2.4.7
FileDescription: Organization Daydreams Holding Invisible
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Blocker.ldfa also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005390201 )
LionicTrojan.Win32.Blocker.j!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.24300
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.31128754
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.133374
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Blocker.64d80c1c
K7GWTrojan ( 005390201 )
Cybereasonmalicious.5878a7
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/PSW.Delf.OSF
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.ldfa
BitDefenderTrojan.GenericKD.31128754
NANO-AntivirusTrojan.Win32.Blocker.fimxoh
MicroWorld-eScanTrojan.GenericKD.31128754
TencentWin32.Trojan.Blocker.Taey
Ad-AwareTrojan.GenericKD.31128754
SophosMal/Generic-S
ComodoMalware@#3dbmkcxcpn1tr
BitDefenderThetaGen:NN.ZexaF.34058.Cq0@ai1dJ9ei
McAfee-GW-EditionBehavesLike.Win32.Dropper.gc
FireEyeGeneric.mg.ce482185878a7a93
EmsisoftTrojan.GenericKD.31128754 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Blocker.iun
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1137793
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.271AC5F
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Generic.D1DAFCB2
GDataTrojan.GenericKD.31128754
TACHYONRansom/W32.Blocker.470016
Acronissuspicious
McAfeeArtemis!CE482185878A
MAXmalware (ai score=83)
VBA32BScope.TrojanSpy.Zbot
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.90 (RDML:vzKMk/eO0c2mBWdB0uj4cg)
YandexTrojan.Blocker!X6at706AwGE
IkarusTrojan-Ransom.GandCrab
FortinetW32/GenKryptik.CGJW!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASOYA

How to remove Trojan-Ransom.Win32.Blocker.ldfa?

Trojan-Ransom.Win32.Blocker.ldfa removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment