Ransom Trojan

Trojan-Ransom.Win32.Blocker.tosv removal

Malware Removal

The Trojan-Ransom.Win32.Blocker.tosv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.tosv virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Touches a file containing cookies, possibly for information gathering

How to determine Trojan-Ransom.Win32.Blocker.tosv?


File Info:

name: 43886EDF86BEBBBD7B6D.mlw
path: /opt/CAPEv2/storage/binaries/c250e0f7ba5a6a2b4fc602fcdfb2aa5f2153a479c682bdc2a1a507b71b2a26df
crc32: EC04DAFC
md5: 43886edf86bebbbd7b6de7c8d20578a5
sha1: f13a203435b148e11f9498dcc10cd93b8403a270
sha256: c250e0f7ba5a6a2b4fc602fcdfb2aa5f2153a479c682bdc2a1a507b71b2a26df
sha512: f2f1b365bf16c90afa18ed0654f3bde1b2004ee0b44949f06442fe580c86d89d19af9c42e2cf946b37310a6edf98306910da29589afb3fe09ec5425ec4d4b1b2
ssdeep: 196608:89azg7DSm9azg7DSm9azg7DSm9azg7DSN:Jg7uPg7uPg7uPg7uN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B486123AF1D08437D1236E7CCC5BA754A825BEE12D28608A7BED1C09DF39B9125263D7
sha3_384: d5808ac4faacd3fe894bb4c7261bff3ab9064c2b1718a740d26881e2a4a06200a86ed3e0ff3970952d50e54cbf1f3949
ep_bytes: 55545d906a2890596a006a004975f953
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Blocker.tosv also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader6.7779
MicroWorld-eScanGen:Variant.Symmi.34741
FireEyeGeneric.mg.43886edf86bebbbd
CAT-QuickHealTrojan.IgenericPMF.S24498703
SkyhighBehavesLike.Win32.Generic.wc
ALYacGen:Variant.Symmi.34741
Cylanceunsafe
ZillyaTrojan.Blocker.Win32.94983
SangforRansom.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Starter.ali1001008
K7GWRiskware ( 0040eff71 )
K7AntiVirusTrojan ( 00548e051 )
BitDefenderThetaAI:Packer.DC953A6A21
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.ERFT
APEXMalicious
ClamAVWin.Trojan.Mbrlock-9779766-0
KasperskyTrojan-Ransom.Win32.Blocker.tosv
BitDefenderGen:Variant.Symmi.34741
NANO-AntivirusTrojan.Win32.Dapato.bsjzfg
TencentTrojan.Win32.Blocker.zg
TACHYONRansom/W32.Blocker.8317440
VIPREGen:Variant.Symmi.34741
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Symmi.34741 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.trx
VaristW32/Injector.OZVT-2500
AviraHEUR/AGEN.1369747
MicrosoftTrojan:Win32/Injector.INK!MTB
XcitiumTrojWare.Win32.Injector.HO@82j6jo
ArcabitTrojan.Symmi.D87B5
ZoneAlarmTrojan-Ransom.Win32.Blocker.tosv
GDataGen:Variant.Symmi.34741
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win32.Dapato.R83155
McAfeeGenericRXIP-BJ!43886EDF86BE
MAXmalware (ai score=81)
MalwarebytesGeneric.Malware.AI.DDS
RisingTrojan.Injector!1.DA56 (CLASSIC)
YandexTrojan.Injector!6XR9EGb/HqY
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.124870659.susgen
FortinetW32/Injector.AHHO!tr
PandaTrj/Genetic.gen
alibabacloudBackdoor:Win/Mbrlock.070a0a72

How to remove Trojan-Ransom.Win32.Blocker.tosv?

Trojan-Ransom.Win32.Blocker.tosv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment