Ransom Trojan

Trojan-Ransom.Win32.Blocker.zhjc removal tips

Malware Removal

The Trojan-Ransom.Win32.Blocker.zhjc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Blocker.zhjc virus can do?

  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Trojan-Ransom.Win32.Blocker.zhjc?


File Info:

name: FACFE66852B85FC0FDB7.mlw
path: /opt/CAPEv2/storage/binaries/5392096f047c12d13c7f65b173a3d941d5161ae0bb5d36e5c5ac7bb95d4c6f7e
crc32: 5AA239FE
md5: facfe66852b85fc0fdb7a1ee5cfa6b9b
sha1: e4207adba17cc6ae248293f8f8be3c5409602c5c
sha256: 5392096f047c12d13c7f65b173a3d941d5161ae0bb5d36e5c5ac7bb95d4c6f7e
sha512: 73fd4475162b6e103276cb3c6fc4dbc534d46cfcda53232ac25a246f67fdcfe587791bfc75f1da283138fdffd1d6ee4f8110abab70cf08b7ff8745b1f0e5bc22
ssdeep: 768:SEHNUk59kkkkEvkkIhswkkkkkkkkkkkkkskR7M41v1TbpC/fgm3Htx:SEHNdkkkkOkkIhswkkkkkkkkkkkkksMo
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T149B22B69699CC62ED66F4BBC7CB316240371E3825919EB866CCC9DBF196335048313E7
sha3_384: 6bcdfdef748c17430735001169be1dc4c305237c89d82af4a3253bea17a6c6c12e7b5deca3c82dea1a7df1c1c5c7a197
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-03-04 02:33:32

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: braabra.exe
LegalCopyright:
OriginalFilename: braabra.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Trojan-Ransom.Win32.Blocker.zhjc also known as:

LionicTrojan.Win32.Convagent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.65778980
FireEyeTrojan.GenericKD.65778980
SangforTrojan.Win32.Agent.Vg0o
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.zhjc
BitDefenderTrojan.GenericKD.65778980
AvastWin32:Malware-gen
EmsisoftTrojan.GenericKD.65778980 (B)
McAfee-GW-EditionArtemis
Trapminemalicious.high.ml.score
SophosMal/Generic-S
ArcabitTrojan.Generic.D3EBB524
ZoneAlarmTrojan-Ransom.Win32.Blocker.zhjc
GDataWin32.Trojan-Downloader.Generic.OMVLZD
McAfeeArtemis!FACFE66852B8
MAXmalware (ai score=81)
RisingDownloader.Convagent!8.123D1 (CLOUD)
SentinelOneStatic AI – Suspicious PE
FortinetMalicious_Behavior.SB
AVGWin32:Malware-gen

How to remove Trojan-Ransom.Win32.Blocker.zhjc?

Trojan-Ransom.Win32.Blocker.zhjc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment