Ransom Trojan

Trojan-Ransom.Win32.Blocker.tlf information

Malware Removal

The Trojan-Ransom.Win32.Blocker.tlf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.tlf virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Creates known SpyNet mutexes and/or registry changes.
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.Blocker.tlf?


File Info:

crc32: 15A810C9
md5: 1660a5561bbe09d03df96b6f920f8df3
name: 1660A5561BBE09D03DF96B6F920F8DF3.mlw
sha1: 11872df7857f4307cfb851236ed8764cba0c31bb
sha256: 859fe5d418c1349417a89542cbbf78c9ebc95388f9b8bab74d09b399dbefc976
sha512: b5ac7861e7031344efec151a79b06896fe1d8b7caf0b57282bbc42a1adc2e06afb29f507e03bd664471c38bd1fe0b94e6668e10a893f1bfb287b02d5a352363c
ssdeep: 12288:d+w1XgXtv6SD4WEKyK7I78IhpZ0T+ix5:UwdgXtvzD4WBkLZEx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: 1
FileVersion: 1.00
OriginalFilename: 1.exe
ProductName: malditos

Trojan-Ransom.Win32.Blocker.tlf also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 0056cb291 )
Elasticmalicious (high confidence)
DrWebTrojan.Virtumod.11842
CynetMalicious (score: 100)
ALYacGen:Variant.Symmi.15273
CylanceUnsafe
ZillyaTrojan.Bublik.Win32.6838
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Blocker.821d5194
K7GWSpyware ( 0056cb291 )
Cybereasonmalicious.61bbe0
CyrenW32/Trojan.LCIS-1941
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ZUS
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Bublik-9847255-0
KasperskyTrojan-Ransom.Win32.Blocker.tlf
BitDefenderGen:Variant.Symmi.15273
NANO-AntivirusTrojan.Win32.Blocker.dyegfx
ViRobotTrojan.Win32.A.Bublik.139264.A
SUPERAntiSpywareTrojan.Agent/Gen-Vbject
MicroWorld-eScanGen:Variant.Symmi.15273
TencentWin32.Trojan.Blocker.Dxmu
Ad-AwareGen:Variant.Symmi.15273
SophosMal/Generic-S
ComodoMalware@#3cox4jctbkcoi
F-SecureHeuristic.HEUR/AGEN.1110558
BitDefenderThetaGen:NN.ZevbaF.34670.ym0@aeH9u5pi
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroTSPY_POISON_BL13033F.TOMC
McAfee-GW-EditionBehavesLike.Win32.VBObfus.fc
FireEyeGeneric.mg.1660a5561bbe09d0
EmsisoftGen:Variant.Symmi.15273 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Bublik.cxx
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1110558
eGambitGeneric.Malware
KingsoftWin32.Troj.Bublik.k.(kcloud)
MicrosoftWorm:Win32/Rebhip.A
ArcabitTrojan.Symmi.D3BA9
AegisLabTrojan.Win32.Blocker.j!c
GDataGen:Variant.Symmi.15273
AhnLab-V3Trojan/Win32.Bublik.R41805
Acronissuspicious
McAfeeTrojan-FAYO!1660A5561BBE
MAXmalware (ai score=100)
VBA32TScope.Trojan.VB
MalwarebytesMachineLearning/Anomalous.96%
PandaTrj/CI.A
TrendMicro-HouseCallTSPY_POISON_BL13033F.TOMC
RisingTrojan.Win32.Generic.13E323C9 (C64:YzY0OqVHV+xS8cjc)
YandexTrojan.GenAsa!2DIdYHY8cYo
IkarusBackdoor.Poison
FortinetW32/Injector.BZKN!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360HEUR/Malware.QVM20.Gen

How to remove Trojan-Ransom.Win32.Blocker.tlf?

Trojan-Ransom.Win32.Blocker.tlf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment