Ransom Trojan

Trojan-Ransom.Win32.Blocker.lkum removal instruction

Malware Removal

The Trojan-Ransom.Win32.Blocker.lkum is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.lkum virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • Code injection with CreateRemoteThread in a remote process
  • Sniffs keystrokes
  • Executed a process and injected code into it, probably while unpacking
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Creates known SpyNet mutexes and/or registry changes.

Related domains:

haso.ddns.net

How to determine Trojan-Ransom.Win32.Blocker.lkum?


File Info:

crc32: 7CC241EF
md5: 89cc4bbe21bbe4428fefc7918f02910e
name: 89CC4BBE21BBE4428FEFC7918F02910E.mlw
sha1: f1091bbb866185adcd2fac0e855cc56432a9adaa
sha256: 431bd4b968f294211c853da11e1d79297834b838e427ac9a4eca4b8ab51becc3
sha512: c4d33d4aa9c9817d3831f456e764c8e32ff5e6acb855ef3d6305775bb888857b949bafdd7fed435dcb36a173e2fef9eeb6fb950d0697f7539beb3c90f5aed6f2
ssdeep: 24576:mLeTcAXypokLnIoO2LykEpoy2nPgprWkfLV:AeTcAXSokLnfO2LykEmy2nPZkfLV
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2002
Assembly Version: 67.45.69.55
InternalName: 55555555.EXE
FileVersion: 11.95.65.86
Comments: WindowsApplication22
ProductName: WindowsApplication22
ProductVersion: 11.95.65.86
FileDescription: WindowsApplication22
OriginalFilename: 55555555.EXE

Trojan-Ransom.Win32.Blocker.lkum also known as:

K7AntiVirusTrojan ( 004be5b21 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.40762699
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.41919
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Blocker.9b44bdf3
K7GWTrojan ( 004be5b21 )
Cybereasonmalicious.e21bbe
CyrenW32/MSIL_Kryptik.DGQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Packed.Confuser.P suspicious
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Hpbladabi-6860330-0
KasperskyTrojan-Ransom.Win32.Blocker.lkum
BitDefenderTrojan.GenericKD.40762699
NANO-AntivirusTrojan.Win32.Blocker.fmrlck
MicroWorld-eScanTrojan.GenericKD.40762699
TencentWin32.Backdoor.Cybergate.Uijs
Ad-AwareTrojan.GenericKD.40762699
SophosMal/Generic-S
ComodoMalware@#2rhqfwdahgu7c
BitDefenderThetaGen:NN.ZemsilF.34758.Ym0@aG3!QFi
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.89cc4bbe21bbe442
EmsisoftTrojan.GenericKD.40762699 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1141908
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASBOL.38BB
MicrosoftBackdoor:Win32/Bladabindi!ml
AegisLabTrojan.Win32.Blocker.4!c
ZoneAlarmTrojan-Ransom.Win32.Blocker.lkum
GDataTrojan.GenericKD.40762699
McAfeeArtemis!89CC4BBE21BB
MAXmalware (ai score=89)
VBA32TScope.Trojan.MSIL
PandaTrj/GdSda.A
YandexTrojan.Blocker!kOgHP+uTTlI
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injecto.58E1!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Blocker.lkum?

Trojan-Ransom.Win32.Blocker.lkum removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment