Ransom

Ransom.Stop.S7866402 information

Malware Removal

The Ransom.Stop.S7866402 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Stop.S7866402 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Serbian
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to execute a powershell command with suspicious parameter/s
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom.Stop.S7866402?


File Info:

crc32: 1C87F7A2
md5: 5b4bd24d6240f467bfbc74803c9f15b0
name: updatewin1.exe
sha1: c17f98c182d299845c54069872e8137645768a1a
sha256: 14c7bec7369d4175c6d92554b033862b3847ff98a04dfebdf9f5bb30180ed13e
sha512: a896acc38a6ff9641b0803f0598369c0d4fa8e38da28c1653c57948fe5e3274880d1b2e7959cd1b1da43375a1318b3ba72e13240bf40b27c852ee72bbb16cadc
ssdeep: 6144:7qZQGv0d4dW6efSyahstfKVkW5XXnXXfXXXWXXXXHXXXXBXXXXgXXXXX5XXXXiX:2ZQGXdPe6qU6W5XXnXXfXXXWXXXXHXX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018, sacuwedimufoy
InternalName: rawudiyeh.exe
FileVersion: 7.7.7.18
Translation: 0x0669 0x04b0

Ransom.Stop.S7866402 also known as:

BkavW32.TiggreRP.Trojan
MicroWorld-eScanTrojan.GenericKD.31534187
FireEyeGeneric.mg.5b4bd24d6240f467
CAT-QuickHealRansom.Stop.S7866402
McAfeeGeneric.bto
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.31534187
K7GWTrojan ( 00545a541 )
K7AntiVirusTrojan ( 00545a541 )
TrendMicroTrojan.Win32.MALREP.THOABAAI
BitDefenderThetaGen:NN.ZexaF.34084.ru0@a8IEJKdG
F-ProtW32/Kryptik.PT.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32Win32/Agent.AAFU
TrendMicro-HouseCallTrojan.Win32.MALREP.THOABAAI
Paloaltogeneric.ml
GDataWin32.Packed.Kryptik.3IRJVU
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Fareit.12616b27
NANO-AntivirusTrojan.Win32.Stealer.fmbxlx
ViRobotTrojan.Win32.S.GandCrab.279040
AegisLabTrojan.Win32.Generic.4!c
RisingTrojan.Kryptik!1.B582 (KTSE)
Ad-AwareTrojan.GenericKD.31534187
EmsisoftTrojan.GenericKD.31534187 (B)
ComodoMalware@#syoy7tb6o5oy
F-SecureTrojan.TR/Crypt.Agent.iyodi
DrWebTrojan.PWS.Stealer.24943
ZillyaTrojan.Vilsel.Win32.37830
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.high.ml.score
SophosMal/GandCrab-G
APEXMalicious
CyrenW32/Kryptik.PT.gen!Eldorado
JiangminTrojan.Generic.dcbhq
MaxSecureRansomeware.GandCrypt.JZ
AviraTR/Crypt.Agent.iyodi
Antiy-AVLTrojan[Ransom]/Win32.Chapak.a
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1E12C6B
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AhnLab-V3Win-Trojan/Gandcrab10.Exp
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Fareit.VV!MTB
TACHYONRansom/W32.GandCrab.279040
VBA32BScope.Trojan.Chapak
ALYacTrojan.Ransom.Stop
MAXmalware (ai score=100)
MalwarebytesTrojan.MalPack.GS
PandaTrj/WLT.E
ZonerTrojan.Win32.80450
TencentWin32.Trojan.Generic.Swlf
YandexTrojan.Vilsel!Pew/bXY9iz4
IkarusTrojan-Ransom.Downloader.Stop
eGambitUnsafe.AI_Score_90%
FortinetW32/Generic.AAFU!tr
WebrootW32.Trojan.Gen
AVGOther:Malware-gen [Trj]
Cybereasonmalicious.d6240f
AvastOther:Malware-gen [Trj]
Qihoo-360Win32/Trojan.33f

How to remove Ransom.Stop.S7866402?

Ransom.Stop.S7866402 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment