Threat Database Trojans Trojan.Blocker.B

Trojan.Blocker.B

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 10,593
Threat Level: 80 % (High)
Infected Computers: 1,254
First Seen: March 5, 2022
Last Seen: July 6, 2026
OS(es) Affected: Windows

The detection of Trojan.Blocker.B indicates that your system has been compromised by a potentially malicious program. This type of threat is known to cause significant disruptions to your computer's normal functioning, and it is essential to take immediate action to remove it and prevent further damage.

What Is Trojan.Blocker.B?

Trojan.Blocker.B is a type of Trojan horse, a malicious program that disguises itself as a legitimate application. Once installed, it can allow unauthorized access to your system, steal sensitive information, and disrupt your computer's operation. The name "Trojan.Blocker.B" suggests that it may be designed to block or interfere with certain system functions or security software, but the exact nature of this threat can vary.

How Trojan.Blocker.B Operates

Trojan.Blocker.B, like other Trojans, operates by exploiting vulnerabilities in your system or tricking you into installing it. It may be disguised as a useful program or hidden within another application. Once installed, it can communicate with its creators, allowing them to control your system remotely, steal data, or install additional malware. The specific actions of Trojan.Blocker.B can depend on its design and the intentions of its creators.

Symptoms of Infection

The symptoms of a Trojan.Blocker.B infection can vary but may include slow system performance, frequent crashes, unexpected pop-ups, and changes to your system settings without your consent. You might also notice that your antivirus software or firewall has been disabled, or that certain programs or functions are blocked. In some cases, the infection might not display obvious symptoms, making it harder to detect without a thorough system scan.

How to Remove Trojan.Blocker.B

  1. Boot your computer in Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove all components of the Trojan.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time the infection was detected.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.Blocker.B requires careful and thorough action to ensure that your system is completely cleaned and protected against future infections. By following the steps outlined above and maintaining good computer hygiene, such as regularly updating your software, using strong antivirus protection, and being cautious with emails and downloads, you can significantly reduce the risk of malware infections. Remember, prevention and prompt action are key to protecting your digital assets and personal information.

Analysis Report

General information

Family Name: Trojan.Blocker.B
Signature status: No Signature

Known Samples

MD5: e09712f6a4e99e1e5d113cc0abaa0acd
SHA1: f88493f523d30b3a0096259482c90517762f64e6
SHA256: 9F512AD83CBB590AE28F257DCEC0639F97E07C85979397F0CDFE001087FA8E17
File Size: 5.36 MB, 5364752 bytes
MD5: 4d24624e97fc5a3ebad6bbbb18d5093f
SHA1: d850430167d85d815823d97039c1c2034728351b
SHA256: A1838696C9713EA9EEEA635401A49BFBF0FE703F348CBC93C07D0BC73671565F
File Size: 5.52 MB, 5523472 bytes
MD5: c1becc61f40619fbe3f78d1a39d79d6b
SHA1: bd24eeebe082cffb7d490861cf286ce67611e6db
SHA256: 95F664F50266F99462433D1C4ABE02E96CA51664375C305D1D9AAF74AD5E229E
File Size: 5.52 MB, 5523472 bytes
MD5: a76f594e19650449e8cf6155cbaab31b
SHA1: 2398aa8623e91371bacc041348260fb893a9dfc2
SHA256: A9DC22291D3DAA5EC55E98FCC0BB57B1F0E3B1725BCC945F46042DCD356B6D93
File Size: 5.37 MB, 5365264 bytes
MD5: ff2432d3676078cec0f427f129b30dab
SHA1: b99a3512ae3b0d2f1fcdb9a8d46e2ec3f9020962
SHA256: CF3C657FAAB88596634A8A8ECF80550ECF1B8B1A52DD52A40ECC83E7025C0458
File Size: 5.52 MB, 5523472 bytes
Show More
MD5: d23876a3940725b267fd394d7c171c9c
SHA1: d1ed2642f9935b8a21d9b8ed720afa7c13882998
SHA256: FA0026FAEB656485A2EC5C92F342F6A898482E97C65BDF1E4D9E31B44E637D04
File Size: 5.52 MB, 5522960 bytes
MD5: 20b2bcb9587dbe10a972288ffa9e5b0a
SHA1: 22c12134981b8bfff02b4ac8bfa6f8fd5c3295b5
SHA256: 7FEA33ABC05E3D30C088C6F13619FED5C32E5D820621103F6105EDBD2429F664
File Size: 5.37 MB, 5365776 bytes
MD5: dd13552b6cd4649a1128a94ad6fe34e4
SHA1: 8cd2d78857e7ab8ed3114190e91b296a494f7d57
SHA256: 26A7D0BEDF9095564D7D83A0E317D593BD5530FEDE0F3D7DCB987CBA9F56757B
File Size: 5.53 MB, 5525008 bytes
MD5: 8d66ab3113d1fcdf61316f42ce13d6c4
SHA1: ff9e5583040083964d687a2c397abcbf0a79503b
SHA256: CAB9D71512A5D6F7E963BB8819440908CFBF530029F698ABB24018A096ACCB78
File Size: 5.36 MB, 5364240 bytes
MD5: ee2f6a15e615021934cfebf492886f61
SHA1: 1180cf49083d21f199986ecd942a543bb1129c75
SHA256: EEA146371818B2B6567FE43E83DCB28E54C3072A5A554E5FA7B661551280DBFC
File Size: 5.52 MB, 5523984 bytes
MD5: f60f1c5d822b1ddcc0f42508a990af90
SHA1: de2d9474a2945a9c278d2eeec1f63b2b6aae6dea
SHA256: 5F29E066771D5E9A30D5A9E9215C6032666A629ACFC4690588BC069C12670CB2
File Size: 5.37 MB, 5366288 bytes
MD5: d445859131b9f7b74f8011be0823cda1
SHA1: bde0726755a2d2774615f2fe678f933ec5a257e2
SHA256: B435BA30341E1561EB05F84E2140E0696827CA74AAEDE49056944B757CB61B0B
File Size: 5.36 MB, 5364240 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name The Qt Company Ltd.
File Description C++ Application Development Framework
File Version 5.14.2.0
Legal Copyright Copyright (C) 2020 The Qt Company Ltd.
Original Filename Qt5Core.dll
Product Name Qt5
Product Version 5.14.2.0

File Traits

  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 12,481
Potentially Malicious Blocks: 709
Whitelisted Blocks: 11,755
Unknown Blocks: 17

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x x x x x x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.AIAH

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\f88493f523d30b3a0096259482c90517762f64e6_0005364752.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\d850430167d85d815823d97039c1c2034728351b_0005523472.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\bd24eeebe082cffb7d490861cf286ce67611e6db_0005523472.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\2398aa8623e91371bacc041348260fb893a9dfc2_0005365264.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\b99a3512ae3b0d2f1fcdb9a8d46e2ec3f9020962_0005523472.,LiQMAxHB
Show More
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\d1ed2642f9935b8a21d9b8ed720afa7c13882998_0005522960.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\22c12134981b8bfff02b4ac8bfa6f8fd5c3295b5_0005365776.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\8cd2d78857e7ab8ed3114190e91b296a494f7d57_0005525008.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\ff9e5583040083964d687a2c397abcbf0a79503b_0005364240.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\1180cf49083d21f199986ecd942a543bb1129c75_0005523984.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\de2d9474a2945a9c278d2eeec1f63b2b6aae6dea_0005366288.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\bde0726755a2d2774615f2fe678f933ec5a257e2_0005364240.,LiQMAxHB

Trending

Most Viewed

Loading...