Threat Database Trojans Trojan.Blocker.H

Trojan.Blocker.H

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 2
First Seen: March 14, 2025
Last Seen: December 14, 2025
OS(es) Affected: Windows

The detection of Trojan.Blocker.H indicates that your system has been compromised by a type of malicious software known as a Trojan. This type of threat is designed to deceive users into installing it on their systems, often by disguising itself as a legitimate program or file. Once installed, Trojan.Blocker.H can cause a range of problems, from disrupting system performance to stealing sensitive information.

What Is Trojan.Blocker.H?

Trojan.Blocker.H is a type of Trojan horse malware that can block access to certain system features or applications, while also potentially allowing unauthorized access to your system. The name "Trojan" refers to the fact that this type of malware often relies on social engineering tactics to trick users into installing it. The ".Blocker.H" part of the name suggests that this particular variant may be designed to block certain system functions or applications, although the exact behavior can vary.

How Trojan.Blocker.H Operates

Like other types of Trojans, Trojan.Blocker.H operates by exploiting vulnerabilities in system security or user behavior. It may be installed through a variety of means, including drive-by downloads, infected email attachments, or fake software updates. Once installed, the malware can communicate with its creators, allowing them to remotely control the infected system or steal sensitive information. Trojan.Blocker.H may also be designed to spread to other systems, either through network connections or by infecting removable drives.

Symptoms of Infection

The symptoms of a Trojan.Blocker.H infection can vary, but may include slowed system performance, unexpected crashes or freezes, and unusual network activity. You may also notice that certain system features or applications are blocked or disabled, or that your system is behaving erratically. In some cases, the malware may also display fake error messages or warnings, or attempt to trick you into installing additional malware.

  • Slow system performance or crashes
  • Unusual network activity or connectivity issues
  • Blocked or disabled system features or applications
  • Fake error messages or warnings
  • Unexplained changes to system settings or configuration

How to Remove Trojan.Blocker.H

  1. Boot your system into Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware components.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malware-related extensions or add-ons.
  5. Reboot your system and perform a follow-up scan to ensure that all malware components have been removed.

Conclusion

Removing Trojan.Blocker.H from your system requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined above and using reputable anti-malware tools, you can help to ensure that your system is free from infection and that your sensitive information is protected. Remember to always be cautious when installing new software or opening email attachments, and to keep your system and security software up to date to prevent future infections.

Analysis Report

General information

Family Name: Trojan.Blocker.H
Signature status: No Signature

Known Samples

MD5: 32c9ce920c752db77de65d4ba160c4b3
SHA1: 122dd22beb3eb72336d034d6efed5ebeba3a95b2
SHA256: DD42F250DE7387ABCFB59E1F2995A41B3E001A6188CC8BA8E626BCBC960BD8FA
File Size: 47.62 KB, 47616 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Hiteke
File Description FactorioFix
File Version 1.0.0.1
Internal Name FactorioFix.dll
Legal Copyright Copyright (C) 2024, Hiteke
Original Filename FactorioFix.dll
Product Name FactorioFix
Product Version 1.0.0.1

File Traits

  • dll
  • x64

Block Information

Total Blocks: 136
Potentially Malicious Blocks: 8
Whitelisted Blocks: 128
Unknown Blocks: 0

Visual Map

0 0 0 0 0 x x x 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Network Wininet
  • InternetOpen

Trending

Most Viewed

Loading...