Ransom Trojan

What is “Trojan-Ransom.Win32.Blocker.lkuo”?

Malware Removal

The Trojan-Ransom.Win32.Blocker.lkuo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.lkuo virus can do?

  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
educationaltools.info
icanhazip.com

How to determine Trojan-Ransom.Win32.Blocker.lkuo?


File Info:

crc32: 7AD2FEE5
md5: 2e2b502b8d9a96d244f26cbf520aef83
name: 2E2B502B8D9A96D244F26CBF520AEF83.mlw
sha1: 3bd3fcb540bbd9bff6c0cd3df28c0aa448e70546
sha256: 3f4c15748cb0833ba4efd46c66e525e4ea7f5cd26e9b39f24d06923464517092
sha512: e457de3caef3422c1f0b118eddf210085e033d2ea2a8d80fb4074f219550b557e6adccd1160f6c69e728f348b67e6a4aa45ed0e065af6a5ac11f7f66ec5e89a5
ssdeep: 49152:/UTsamKw9UsbHTo5DUsbHTokUfUsbHTokls:/azw9UkTyDUkTwfUkT5
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: xa9 2003 - 2018 Autism Corp.
FileVersion: 1.3.3.7
Translation: 0x0809 0x04b0

Trojan-Ransom.Win32.Blocker.lkuo also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 004d8c0a1 )
LionicTrojan.Win32.Blocker.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad4.11093
CynetMalicious (score: 100)
CAT-QuickHealTrojanSpy.KeyLogger
ALYacAIT:Trojan.Nymeria.402
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.41245
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Blocker.47e66f31
K7GWSpyware ( 004d8c0a1 )
Cybereasonmalicious.b8d9a9
BaiduMulti.Threats.InArchive
CyrenW32/AutoIt.QV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Autoit-6961072-0
KasperskyTrojan-Ransom.Win32.Blocker.lkuo
BitDefenderAIT:Trojan.GenericTKA.26
NANO-AntivirusTrojan.Win32.AutoIt.fkfvsd
MicroWorld-eScanAIT:Trojan.GenericTKA.26
TencentWin32.Trojan.Blocker.Hrzf
Ad-AwareAIT:Trojan.GenericTKA.26
SophosMal/Generic-S
ComodoMalware@#3v3igckohynlw
BitDefenderThetaAI:Packer.DBCB5E9518
TrendMicroTROJ_GEN.R002C0DE921
McAfee-GW-EditionBehavesLike.Win32.Spyware.tc
FireEyeGeneric.mg.2e2b502b8d9a96d2
EmsisoftAIT:Trojan.GenericTKA.26 (B)
AviraTR/Spy.Autoit.xbpoq
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASCommon.168
MicrosoftPWS:AutoIt/Passup.A
ArcabitAIT:Trojan.GenericTKA.26
GDataAIT:Trojan.Nymeria.402 (5x)
AhnLab-V3Malware/Gen.Generic.C2848149
McAfeeArtemis!2E2B502B8D9A
MAXmalware (ai score=80)
MalwarebytesMalware.AI.2041746974
TrendMicro-HouseCallTROJ_GEN.R002C0DE921
RisingSpyware.AutoLOG/Autoit!1.C9CE (CLASSIC)
IkarusDropper.AutoIt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/AutoIt.CB!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HwsBEpsA

How to remove Trojan-Ransom.Win32.Blocker.lkuo?

Trojan-Ransom.Win32.Blocker.lkuo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment