Ransom Trojan

Trojan-Ransom.Win32.PornoBlocker information

Malware Removal

The Trojan-Ransom.Win32.PornoBlocker is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.PornoBlocker virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Authenticode signature is invalid

How to determine Trojan-Ransom.Win32.PornoBlocker?


File Info:

name: 65C2A3AC72923FDD1216.mlw
path: /opt/CAPEv2/storage/binaries/9685365d4565f7b7b1c650d557c8bbbddf3159db4175a90b63f923a8150df1d7
crc32: DAC54C48
md5: 65c2a3ac72923fdd1216874d163bf8b9
sha1: e8a4d178f9e129fc175c11a28526a2f20e110510
sha256: 9685365d4565f7b7b1c650d557c8bbbddf3159db4175a90b63f923a8150df1d7
sha512: bd2a3d0728d52e4028e703d1237930ec778367e47896baf6b54c215cb6a5c38cc6208a6fd8eb649ac379419c2636c99a7235f8b69a51c7bd248e3c6b82cfd4fe
ssdeep: 96:zH2F4eTCQrpWtgTDPFq+0bWmFUi1ynT/8rq+:zy4XQrlt/0TFxy7Wh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T144352B864BA96577E398FC3C12CBE839DAEB269619E3DC0E4D910097B6391D42C62D70
sha3_384: e8516a0148eaef71ccd1524ba09051d4d1844b436d31076caecc3f4c52e530e86781e9debb4f68b29d8bdca04c3e2e10
ep_bytes: e8000000005b0f6ed30f7ed581c5ef01
timestamp: 2010-11-05 00:25:00

Version Info:

0: [No Data]

Trojan-Ransom.Win32.PornoBlocker also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
DrWebmodification of Win32.Sector.23
MicroWorld-eScanTrojan.SalityStub.F
FireEyeGeneric.mg.65c2a3ac72923fdd
CAT-QuickHealTrojan.Mauvaise.SL1
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 001cddbb1 )
K7GWTrojan ( 001cddbb1 )
Cybereasonmalicious.c72923
BitDefenderThetaAI:FileInfector.A5ECCBAB0E
VirITTrojan.Win32.Generic.BJJU
CyrenW32/Sality.F.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrashBytes.I potentially unwanted
APEXMalicious
TrendMicro-HouseCallTSPY_AGENT_CA082D2E.TOMC
ClamAVWin.Trojan.Small-5420
KasperskyHEUR:Trojan-Ransom.Win32.PornoBlocker.gen
BitDefenderTrojan.SalityStub.F
AvastWin32:Agent-APKD [Trj]
TencentTrojan.Win32.Small.ha
Ad-AwareTrojan.SalityStub.F
SophosML/PE-A + Mal/Agent-ABC
ComodoTrojWare.Win32.Salrenmetie.A@4w2swt
BaiduWin32.Trojan.Small.a
VIPRETrojan.SalityStub.F
TrendMicroTSPY_AGENT_CA082D2E.TOMC
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.SalityStub.F (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Small.oace.a
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASBOL.3762
MicrosoftTrojan:Win32/Wacatac.B!ml
ViRobotTrojan.Win32.SalityNHost.99328
GDataTrojan.SalityStub.F
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Small.R10023
Acronissuspicious
ALYacTrojan.SalityStub.F
MalwarebytesTrojan.Agent
RisingTrojan.Win32.Fednu.cua (CLASSIC)
YandexTrojan.GenAsa!5Tj45QuXiP0
IkarusTrojan.Win32.Salrenmetie
MaxSecureVirus.Sality.AA
FortinetW32/Agent.ABC!tr
AVGWin32:Agent-APKD [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan-Ransom.Win32.PornoBlocker?

Trojan-Ransom.Win32.PornoBlocker removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment