Ransom Trojan

Trojan-Ransom.Win32.Blocker.wwwp information

Malware Removal

The Trojan-Ransom.Win32.Blocker.wwwp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.wwwp virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Uses IOCTL_SCSI_PASS_THROUGH control codes to manipulate drive/MBR which may be indicative of a bootkit
  • Installs itself for autorun at Windows startup
  • Checks for the presence of known devices from debuggers and forensic tools
  • Harvests cookies for information gathering

How to determine Trojan-Ransom.Win32.Blocker.wwwp?


File Info:

name: 60B33452295071370790.mlw
path: /opt/CAPEv2/storage/binaries/6c1962c581069710a899673c73d40537395c3b4e3d9dc7c41b5ac49c0d8076af
crc32: 4D7F4CF0
md5: 60b33452295071370790c3affdb8dd8e
sha1: 365a318e38c1d38e134c730093eabfaef9ded708
sha256: 6c1962c581069710a899673c73d40537395c3b4e3d9dc7c41b5ac49c0d8076af
sha512: 81149f447c1b0b7d1fba907c5f040a09db9bbf00bdaa39a8903c73d88a26572f46db2dd499da620b5657711c6a0d4de03d4f433ebad41207998d7676a90e1e14
ssdeep: 384:cbCEXMMADQIrUeNFwx9E5xtT6fkCMst8AdxIiv4dK8y8KG8szTO4Am7UnwtzwGom:01NAUsbxtT6sFst/3IrdlLUwqiDnbcu5
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T182A2D092E5AB8D23D39F113F5A8FF62A4D50221FE664CB5175AC303B0C56B9C9C3A076
sha3_384: 02e333ec207a59c2c56b01c517134d66e29b85beef7f61afd2905a04088fd7d862455e95844db43a65b168ab7144078b
ep_bytes: 60be15a040008dbeeb6fffff5789e58d
timestamp: 2009-02-07 06:33:02

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Blocker.wwwp also known as:

FireEyeAdware.GenericKD.38892011
McAfeeArtemis!60B334522950
SangforTrojan.Win32.Sabsik.TE
K7AntiVirusTrojan ( 005814661 )
BitDefenderAdware.GenericKD.38892011
K7GWTrojan ( 005814661 )
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/KillFiles.NPL
TrendMicro-HouseCallTROJ_GEN.R067H0CB422
CynetMalicious (score: 99)
KasperskyTrojan-Ransom.Win32.Blocker.wwwp
MicroWorld-eScanAdware.GenericKD.38892011
Ad-AwareAdware.GenericKD.38892011
SophosGeneric PUA DG (PUA)
DrWebTrojan.DownLoader3.9530
McAfee-GW-EditionBehavesLike.Win32.Dropper.mc
EmsisoftAdware.GenericKD.38892011 (B)
APEXMalicious
JiangminTrojanDropper.BAT.Dmenu.k
MaxSecureTrojan.Malware.300983.susgen
AviraBAT/Killfiles.liurq
MAXmalware (ai score=69)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftBackdoor:Win32/Aicat.A!ml
GDataAdware.GenericKD.38892011
SentinelOneStatic AI – Malicious PE
ALYacAdware.GenericKD.38892011
PandaTrj/CI.A
IkarusTrojan.BAT.KillFiles
FortinetBAT/KillFiles.NPL!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen

How to remove Trojan-Ransom.Win32.Blocker.wwwp?

Trojan-Ransom.Win32.Blocker.wwwp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment