Ransom

Ransom.Stop.Generic malicious file

Malware Removal

The Ransom.Stop.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Ransom.Stop.Generic virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Steals private information from local Internet browsers
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom.Stop.Generic?


File Info:

crc32: 475DDF7B
md5: f4d5c732b89e7caaa53d18dba071df10
name: upp.exe
sha1: 5a087a3ff211bc4aedb5c2b837091b35bfc92120
sha256: 19de4ea70d30d9c4163c593a76101058ef28839a226eb7d92021c67e6e832304
sha512: 3a8e08388412d598cc7c8841f24a8c9f2496000752b2f6557e43474878d7a5538d3fd4d83c4dfb51994347cfc9caf8e5824510e22e72e0ae1e4ac445e5f2c76d
ssdeep: 3072:lsNocLcR/+M6gqx+nBNfp415wYV5W4N88KU5edNqjjjjjjjEwxS5YA:lsNvcRGzjxEA15wg5W4+RU5S1qA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileOldVersionTree: 1.0.4.4
InternalNameTwo: gjtrrh.exe
Translation: 0x0842 0x04c4

Ransom.Stop.Generic also known as:

DrWebTrojan.PWS.Stealer.24273
MicroWorld-eScanTrojan.GenericKD.42039164
CAT-QuickHealTrojanpws.Azorult
McAfeeRDN/Generic PWS.y
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0055be5e1 )
AlibabaTrojan:Win32/Kryptik.2632b4eb
K7GWTrojan ( 0055be5e1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D281777C
BitDefenderThetaGen:NN.ZexaF.32515.nyW@aOPj9jk
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GYQI
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Generickdz-7406516-0
KasperskyTrojan-PSW.Win32.Azorult.afvm
BitDefenderTrojan.GenericKD.42039164
RisingTrojan.Kryptik!1.BE74 (CLASSIC)
Ad-AwareTrojan.GenericKD.42039164
ComodoMalware@#3jp8c65gg341e
F-SecureTrojan.TR/Kryptik.fbfih
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FortinetW32/Kryptik.GYQI!tr
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.f4d5c732b89e7caa
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.SmokeLoader
JiangminTrojan.PSW.Tepfer.kdn
WebrootW32.Trojan.GenKD
AviraTR/Kryptik.fbfih
MAXmalware (ai score=100)
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Gepys.PVS!MTB
ViRobotTrojan.Win32.Z.Kryptik.212992.PT
ZoneAlarmTrojan-PSW.Win32.Azorult.afvm
AhnLab-V3Trojan/Win32.MalPe.R300348
Acronissuspicious
VBA32BScope.Backdoor.Predator
ALYacSpyware.Infostealer.Azorult
MalwarebytesRansom.Stop.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R011C0PKN19
SentinelOneDFI – Suspicious PE
GDataWin32.Trojan.Kryptik.ON
AVGFileRepMalware
Cybereasonmalicious.ff211b
AvastFileRepMalware
Qihoo-360Win32/Trojan.PSW.f43

How to remove Ransom.Stop.Generic?

Ransom.Stop.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment