Ransom Trojan

How to remove “TrojanRansom.MSIL.Blocker”?

Malware Removal

The TrojanRansom.MSIL.Blocker is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanRansom.MSIL.Blocker virus can do?

  • Network activity detected but not expressed in API logs

How to determine TrojanRansom.MSIL.Blocker?


File Info:

crc32: 0EB8D1C7
md5: c2f831dbbb65f6a629d4250526c29dfc
name: C2F831DBBB65F6A629D4250526C29DFC.mlw
sha1: 28f41fcdb11c16eb4c7132c48469dfa5eb5b7023
sha256: 3d94bb6d1766d033fe58f8e9ea0f9e6c2ec5d84aef65293d92fb34ce46ed5342
sha512: 60a29f9ac0f7e6d80f9071c168ae1bb1d5b71916abd9d86a8eb82ec0feb1c984a5463a50e0eb2e40bab503f2bd1aeacd57c412cad6c79cf1fdebfa1412f17b7c
ssdeep: 6144:n7rgJqmTtcVjkHdChkvbj2fHZUQc6O0czJwKNHsbd6LAjB:n3gAmpcVjkHdkkvmx/22+Ud6L
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018 Sunoco Inc.
Assembly Version: 0.0.0.0
InternalName: Advice_Copy.exe
FileVersion: 18.3.11.1
CompanyName: Sunoco Inc.
Comments: oqojetinepeyusubayadoy
ProductName: ISAPI filter module
ProductVersion: 18.3.11.1
FileDescription: ISAPI filter module
OriginalFilename: Advice_Copy.exe

TrojanRansom.MSIL.Blocker also known as:

K7AntiVirusTrojan ( 00540f7f1 )
LionicTrojan.MSIL.Blocker.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.MSIL.Basic.1.Gen
CylanceUnsafe
ZillyaAdware.Blocker.Win32.9
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:MSIL/Kryptik.97b2a097
K7GWTrojan ( 00540f7f1 )
Cybereasonmalicious.bbb65f
CyrenW32/MSIL_Troj.OE.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.PWP
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Ransom.MSIL.Blocker.gen
BitDefenderTrojan.MSIL.Basic.1.Gen
MicroWorld-eScanTrojan.MSIL.Basic.1.Gen
Ad-AwareTrojan.MSIL.Basic.1.Gen
SophosMal/Generic-S
ComodoMalware@#2polwi2p1ligp
BitDefenderThetaGen:NN.ZemsilF.34796.Dm0@aKmM@jg
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_FRS.VSN12J18
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
FireEyeGeneric.mg.c2f831dbbb65f6a6
EmsisoftTrojan.MSIL.Basic.1.Gen (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.krre
AviraHEUR/AGEN.1129514
Antiy-AVLTrojan/Generic.ASMalwS.28C5766
MicrosoftTrojan:Win32/AgentTesla!ml
ArcabitTrojan.MSIL.Basic.1.Gen
GDataTrojan.MSIL.Basic.1.Gen
Acronissuspicious
McAfeeArtemis!C2F831DBBB65
MAXmalware (ai score=100)
VBA32TrojanRansom.MSIL.Blocker
MalwarebytesTrojan.PasswordStealer.MSIL.Generic
TrendMicro-HouseCallTROJ_FRS.VSN12J18
YandexTrojan.Kryptik!HvCRX7vp6N4
IkarusTrojan-Spy.LokiBot
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.PVO!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HwMAEpsA

How to remove TrojanRansom.MSIL.Blocker?

TrojanRansom.MSIL.Blocker removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment