Ransom Trojan

Trojan-Ransom.Win32.Blocker.liwk removal instruction

Malware Removal

The Trojan-Ransom.Win32.Blocker.liwk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.liwk virus can do?

  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Ransom.Win32.Blocker.liwk?


File Info:

crc32: 324AC43F
md5: 77b8760b01a446bb978a5653fe697ade
name: 77B8760B01A446BB978A5653FE697ADE.mlw
sha1: b345a8242c6ff95ea984559a3408b6e32bd41269
sha256: 982720e384bcf16a226ff42194964aa2c33778ab9376438172f2f09927f37ac3
sha512: 81189e32122d629b49b26e5fbc544b36fea3b12fa2d6ada9df6a0b77850332629f3f75e13c0408e7010ca570e4750ffb0f8181d28cb6e1de92a87e7a336b3b6e
ssdeep: 12288:gh1Lk70TnvjcuUxpVZ4bbaaPJCKlwNiYNYtf8na/sg0Tkv1:ck70Trct2bbaaBCKOIvtf8W0oN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Microsoft Corporation. All rights reserved.
Assembly Version: 11.0.0.0
InternalName: dxtrans.exe
FileVersion: 11.0.0.0
ProductName: Internet Explorer
ProductVersion: 11.0.0.0
FileDescription: DirectX Media DirectX Transform Core
OriginalFilename: dxtrans.exe

Trojan-Ransom.Win32.Blocker.liwk also known as:

K7AntiVirusTrojan ( 0053b94a1 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop8.35410
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.31288195
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.40726
AlibabaRansom:Win32/Blocker.1ced93fe
K7GWTrojan ( 0053b94a1 )
Cybereasonmalicious.b01a44
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.DYL
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.liwk
BitDefenderTrojan.GenericKD.31288195
NANO-AntivirusTrojan.Win32.Blocker.fjcqyz
MicroWorld-eScanTrojan.GenericKD.31288195
TencentWin32.Trojan.Blocker.Ajlw
Ad-AwareTrojan.GenericKD.31288195
SophosMal/Generic-S
ComodoMalware@#1g5qqqfzp2f01
BitDefenderThetaGen:NN.ZexaF.34686.Gq2@au9@r2p
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.31288195
EmsisoftTrojan.GenericKD.31288195 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Malware.Gen
MicrosoftTrojan:Win32/Occamy.C
AegisLabTrojan.Win32.Blocker.4!c
GDataTrojan.GenericKD.31288195
AhnLab-V3Trojan/Win32.Agent.R239400
Acronissuspicious
McAfeeArtemis!77B8760B01A4
MAXmalware (ai score=85)
PandaTrj/CI.A
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.Blocker!ZgyizrUYUHE
IkarusTrojan-Dropper.MSIL.Agent
FortinetW32/Blocker.DYL!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Blocker.liwk?

Trojan-Ransom.Win32.Blocker.liwk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment