Ransom Trojan

Trojan-Ransom.Win32.Blocker.lmhd removal

Malware Removal

The Trojan-Ransom.Win32.Blocker.lmhd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.lmhd virus can do?

  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.Blocker.lmhd?


File Info:

crc32: 04B6AC2D
md5: 9a05fb26389b4bc53f543afa0d5f1425
name: 9A05FB26389B4BC53F543AFA0D5F1425.mlw
sha1: a160221eb4809bf4812f3ff7bc7215dbc3350961
sha256: 44b7b10b77c4a100a647d080851f4b811801bc2326b82d2ad8b7459fefebe2d3
sha512: 1e17a037f2d5e77be0fffb3b82cbbfa5a1e168d8380779248012078bbf8870d79e35eecbaa713d73a3abc748817ef4baa9c4d4831a33d61de6372d4afbba0693
ssdeep: 49152:zltjOtn9+AOhf4B8iqjPC6gVfu0DDVYq0011YE:zHywO2jCVp6q0wYE
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Blocker.lmhd also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004f787d1 )
Elasticmalicious (high confidence)
DrWebBackDoor.Bladabindi.13678
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.30660759
CylanceUnsafe
SangforBackdoor.Win32.Bladabindi.8
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 004f787d1 )
Cybereasonmalicious.6389b4
SymantecBackdoor.Ratenjay
ESET-NOD32MSIL/Bladabindi.BH
APEXMalicious
AvastScript:SNH-gen [Trj]
KasperskyTrojan-Ransom.Win32.Blocker.lmhd
BitDefenderTrojan.GenericKD.30660759
NANO-AntivirusTrojan.Script.Agent.fkwnyf
MicroWorld-eScanTrojan.GenericKD.30660759
TencentWin32.Trojan.Generic.Hsif
Ad-AwareTrojan.GenericKD.30660759
SophosGeneric ML PUA (PUA)
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.9a05fb26389b4bc5
EmsisoftTrojan.GenericKD.30660759 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Cossta.aji
AviraHEUR/AGEN.1112142
MicrosoftBackdoor:MSIL/Bladabindi
ArcabitTrojan.Generic.D1D3D897
AegisLabTrojan.Script.Generic.4!c
GDataTrojan.GenericKD.30660759
McAfeeArtemis!9A05FB26389B
MAXmalware (ai score=96)
VBA32Backdoor.Bladabindi
PandaTrj/CI.A
FortinetVBS/Kryptik.HZ!tr
AVGScript:SNH-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Blocker.lmhd?

Trojan-Ransom.Win32.Blocker.lmhd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment