Ransom Trojan

How to remove “Trojan-Ransom.Win32.Blocker.lkgl”?

Malware Removal

The Trojan-Ransom.Win32.Blocker.lkgl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.lkgl virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz

How to determine Trojan-Ransom.Win32.Blocker.lkgl?


File Info:

crc32: 39919397
md5: e25fd4a03bf5b4571dc8ba063c5b29fe
name: E25FD4A03BF5B4571DC8BA063C5B29FE.mlw
sha1: 4cc56a84e54becfae8195197a3626bac366dffd6
sha256: d7d09bfc3b55773d6c187d89a702e49580667cb803695b13a7206035a3b75162
sha512: 71c2dd0e5cce37b8ed58f64097e75310d4f22b061e6cf71b166fb9364b3a10072eb272f39c71918387e6b50dbfbaba1057e7c383c9a640b6b4b81077c243e9f4
ssdeep: 12288:sh1Lk70TnvjcOUR8kTlqlXm32M4VV+yz4t3ZzxLcE8nYeSwDO2GyKecRo:Yk70Trc0YMWH6VdEfVLcE8Ye5O2Kjq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (c) 2006-2011 Apple Inc. All rights reserved.
InternalName: Apple Software Update
FileVersion: 2.1.3
CompanyName: Apple Inc.
ProductName: Apple Software Update
ProductVersion: 2.1.3
FileDescription: Apple Software Update
OriginalFilename: SoftwareUpdate.exe
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Blocker.lkgl also known as:

BkavW32.AIDetect.malware2
K7AntiVirusPassword-Stealer ( 004d8d6a1 )
LionicTrojan.Win32.Blocker.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader26.61699
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.40668107
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.41797
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Blocker.0aa8baf2
K7GWPassword-Stealer ( 004d8d6a1 )
Cybereasonmalicious.03bf5b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/PSW.CoinStealer.AA
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.lkgl
BitDefenderTrojan.GenericKD.40668107
NANO-AntivirusTrojan.Win32.CoinStealer.fkaakz
MicroWorld-eScanTrojan.GenericKD.40668107
TencentWin32.Trojan.Blocker.Ahyd
Ad-AwareTrojan.GenericKD.40668107
SophosMal/Generic-S
ComodoMalware@#3gkblbbv21io0
BitDefenderThetaGen:NN.ZexaF.34170.Sq0@aCQVHjo
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
FireEyeGeneric.mg.e25fd4a03bf5b457
EmsisoftTrojan.GenericKD.40668107 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1126167
Antiy-AVLTrojan/Generic.ASMalwS.28C7B70
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Generic.D26C8BCB
GDataTrojan.GenericKD.40668107
Acronissuspicious
McAfeeArtemis!E25FD4A03BF5
MAXmalware (ai score=88)
PandaTrj/CI.A
RisingTrojan.Generic@ML.100 (RDML:AfzupSrqo4tgdX5ah4HKtQ)
YandexTrojan.Blocker!UGN7b5IrA6s
IkarusTrojan.MSIL.PSW
FortinetMSIL/CoinStealer.AA!tr.pws
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Blocker.lkgl?

Trojan-Ransom.Win32.Blocker.lkgl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment