Ransom Trojan

What is “Trojan-Ransom.Win32.Blocker.ndmx”?

Malware Removal

The Trojan-Ransom.Win32.Blocker.ndmx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.ndmx virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Touches a file containing cookies, possibly for information gathering

How to determine Trojan-Ransom.Win32.Blocker.ndmx?


File Info:

name: 841AFB5B9F31FDB03DEB.mlw
path: /opt/CAPEv2/storage/binaries/3b183043b09e989dc505572a41e63e8a32b430508a054892cc83a897c1107385
crc32: 1CD5BD5B
md5: 841afb5b9f31fdb03deb4ea4ea092720
sha1: d6965bf9f26b26b7ffcb8eb00e59dabf07f838c3
sha256: 3b183043b09e989dc505572a41e63e8a32b430508a054892cc83a897c1107385
sha512: 1a2383094dcb6e1ad73fbbcffde92bea435737caf6c722e5671d6f1dce10fb6f0f36cb2da90a744b6628f7c6683e62950fa3f34c0b8d58138277552007e1a7b4
ssdeep: 196608:8Aazg7DSmAazg7DSmAazg7DSmAazg7DSN:mg7usg7usg7usg7uN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B686123AF1D08437D1236E7CCC5BA754A825BEE12D28608A7BED1C09DF39B9125263D7
sha3_384: 950bbd8587353cffa2a5d324b876696d805e0e6bc3994d4ca4a38d394163f96fd21bf11f75425ff14ace75d0a4bd72eb
ep_bytes: 55545d906a2890596a006a004975f953
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Blocker.ndmx also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Blocker.j!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.34741
CAT-QuickHealTrojan.IgenericPMF.S24498703
SkyhighBehavesLike.Win32.Generic.wc
ALYacGen:Variant.Symmi.34741
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Blocker.Win32.73338
SangforRansom.Win32.Save.a
K7AntiVirusTrojan ( 00548e051 )
BitDefenderGen:Variant.Symmi.34741
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.9f26b2
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.ERFT
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Mbrlock-9779766-0
KasperskyTrojan-Ransom.Win32.Blocker.ndmx
AlibabaTrojan:Win32/Starter.ali1001008
NANO-AntivirusTrojan.Win32.Dapato.bsjzfg
RisingTrojan.Injector!1.DA56 (CLASSIC)
TACHYONRansom/W32.Blocker.8317440
SophosTroj/Inject-JDR
F-SecureHeuristic.HEUR/AGEN.1369747
DrWebTrojan.DownLoader6.7779
VIPREGen:Variant.Symmi.34741
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.841afb5b9f31fdb0
EmsisoftGen:Variant.Symmi.34741 (B)
IkarusTrojan.Win32.Injector
JiangminTrojan.Blocker.trx
VaristW32/Injector.OZVT-2500
AviraHEUR/AGEN.1369747
Antiy-AVLGrayWare/Win32.Kryptik.ahho
Kingsoftmalware.kb.a.998
MicrosoftTrojan:Win32/Injector.INK!MTB
XcitiumTrojWare.Win32.Injector.HO@82j6jo
ArcabitTrojan.Symmi.D87B5
ZoneAlarmTrojan-Ransom.Win32.Blocker.ndmx
GDataWin32.Trojan.PSE.61HB7B
GoogleDetected
AhnLab-V3Dropper/Win32.Dapato.R83155
McAfeeGenericRXIP-BJ!841AFB5B9F31
MAXmalware (ai score=84)
DeepInstinctMALICIOUS
VBA32TrojanRansom.Blocker
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan.Win32.Blocker.zg
YandexTrojan.Injector!6XR9EGb/HqY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.124870659.susgen
FortinetW32/Injector.AHHO!tr
BitDefenderThetaAI:Packer.DC953A6A21
AVGWin32:MBRlock-DV [Trj]
AvastWin32:MBRlock-DV [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan-Ransom.Win32.Blocker.ndmx?

Trojan-Ransom.Win32.Blocker.ndmx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment