Ransom Trojan

UDS:Trojan-Ransom.Win32.Blocker.gfhu (file analysis)

Malware Removal

The UDS:Trojan-Ransom.Win32.Blocker.gfhu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-Ransom.Win32.Blocker.gfhu virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Authenticode signature is invalid

How to determine UDS:Trojan-Ransom.Win32.Blocker.gfhu?


File Info:

name: 2012FB84FCE8465C89CA.mlw
path: /opt/CAPEv2/storage/binaries/07b530c3ff00e9af0d196308b554705acb7638f4d5ea59a66efa94ddb84aef38
crc32: 16A7FE7D
md5: 2012fb84fce8465c89ca167ed1a16192
sha1: de1777cf108be3b40d257b6ce160da291bed8c8c
sha256: 07b530c3ff00e9af0d196308b554705acb7638f4d5ea59a66efa94ddb84aef38
sha512: 97236560f8c6aeafee3e05719a515afd2433405e94554fd2160b723cdca601f337fb1e4d81282b6f5d3a86f42e493261ae0a48f6f219f1f82db0381b6d2251a9
ssdeep: 1536:jPk5MauJMQ8pzcOZxouNWmlDjixObcracM9k:jPkua08pz57ouNWQjT8jak
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10173F14B0895E56FDA7A3035312B92CE4E676FF717D5716F3AB04AAA3CB02387A1D005
sha3_384: dd6d1d20fe11b7990c70ac74a824fe5393ca5fd8d82d9cba0acec890f1abb4d68aca5a07760acdf9ee72a845ada2a1fa
ep_bytes: e800000000580f6ee80f7eea81c28502
timestamp: 2010-11-05 00:25:00

Version Info:

0: [No Data]

UDS:Trojan-Ransom.Win32.Blocker.gfhu also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanWin32.Sality.3
ClamAVWin.Trojan.Small-5420
FireEyeGeneric.mg.2012fb84fce8465c
CAT-QuickHealTrojan.Mauvaise.SL1
CylanceUnsafe
VIPREWin32.Sality.3
SangforVirus_Suspicious.Win32.Sality.bh
K7AntiVirusTrojan ( 001cddbb1 )
K7GWTrojan ( 001cddbb1 )
Cybereasonmalicious.4fce84
BaiduWin32.Virus.Sality.gen
VirITWin32.Sality.BI
CyrenW32/Sality.gen2
SymantecW32.Sality.AE
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Sality.NBE
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan-Ransom.Win32.Blocker.gfhu
BitDefenderWin32.Sality.3
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Agent-APKD [Trj]
TencentVirus.Win32.TuTu.tv
Ad-AwareWin32.Sality.3
TACHYONVirus/W32.Sality.D
EmsisoftWin32.Sality.3 (B)
ComodoTrojWare.Win32.Salrenmetie.A@4w2swt
DrWebmodification of Win32.Sector.23
TrendMicroPE_SALITY.SM-O
McAfee-GW-EditionBehavesLike.Win32.Ardurk.lh
Trapminemalicious.high.ml.score
SophosMal/Sality-D
SentinelOneStatic AI – Malicious PE
GDataWin32.Sality.3
JiangminWin32/HLLP.Kuku.poly2
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASCommon.3D
ArcabitWin32.Sality.3
ViRobotWin32.Sality.Gen.A
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Small.R10023
McAfeePWS-Zbot.gen.yh
MAXmalware (ai score=80)
MalwarebytesMalware.AI.1461866432
TrendMicro-HouseCallPE_SALITY.SM-O
RisingVirus.Sality/Debris!1.A12C (CLASSIC)
IkarusTrojan.Win32.Salrenmetie
MaxSecureVirus.Sality.AA
FortinetW32/CoinMiner.BH
BitDefenderThetaAI:FileInfector.A5ECCBAB0E
AVGWin32:Agent-APKD [Trj]
PandaW32/Sality.AA
CrowdStrikewin/malicious_confidence_100% (W)

How to remove UDS:Trojan-Ransom.Win32.Blocker.gfhu?

UDS:Trojan-Ransom.Win32.Blocker.gfhu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment