Ransom

Ransom.StopcryptRI.S27595683 removal instruction

Malware Removal

The Ransom.StopcryptRI.S27595683 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.StopcryptRI.S27595683 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Manipuri
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Ransom.StopcryptRI.S27595683?


File Info:

name: FA46D6D2450B9EAFBB66.mlw
path: /opt/CAPEv2/storage/binaries/ae943d0a626dca424ec19cd0f7bf24560943e93e309c5c167dcb15e67f3099d5
crc32: 33C5E483
md5: fa46d6d2450b9eafbb66846701d48571
sha1: c688cde0db543e73e7ebe2f28b4e527cd2606aca
sha256: ae943d0a626dca424ec19cd0f7bf24560943e93e309c5c167dcb15e67f3099d5
sha512: 59936a58f82794a304cc77a45f74bc764420674ea1912a88f409eadf3f6e27f606be147c390745bd2adc3be370674bd63d99d2474f71aa33480acbeee4d12ed2
ssdeep: 1536:5SQukcsVBV+5j67nJCs1yPsT0lg9xmlHkCnIO2rQohlpgg1FHKPsgwZd2RCArKy:5SXuV8WqCmJ2rQohlqOFHKPsHIX5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12B24BE123382D8B1D097563068B5CAA12A7BBC726775445FB7B83B3E2E703C16AF5352
sha3_384: 616d17720f3bb78296955c11885bcb8ad3d83f9a7a3ace050b48559ad37c8b928519be485e85ab24c5af9f5388bde0c6
ep_bytes: e86a4c0000e989feffff8bff558bec51
timestamp: 2021-02-12 06:36:02

Version Info:

FileVersion: 39.42.15.19
Copyrighz: Copyright (C) 2022, pazkarte
ProjectVersion: 25.13.80.11

Ransom.StopcryptRI.S27595683 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Strab.4!c
tehtrisGeneric.Malware
DrWebTrojan.DownLoader44.49352
MicroWorld-eScanTrojan.GenericKDZ.86263
CAT-QuickHealRansom.StopcryptRI.S27595683
McAfeePacked-GDT!FA46D6D2450B
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3733755
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00590e3c1 )
AlibabaRansom:Win32/StopCrypt.2eed2dee
K7GWTrojan ( 00590e3c1 )
Cybereasonmalicious.0db543
VirITTrojan.Win32.Genus.LEQ
CyrenW32/Strab.A.gen!Eldorado
SymantecPacked.Generic.525
Elasticmalicious (high confidence)
ESET-NOD32Win32/Smokeloader.F
TrendMicro-HouseCallRansom.Win32.STOP.FP
Paloaltogeneric.ml
ClamAVWin.Packed.Pwsx-9943150-0
KasperskyHEUR:Trojan.Win32.Strab.gen
BitDefenderTrojan.GenericKDZ.86263
NANO-AntivirusTrojan.Win32.Kryptik.jnxkhl
AvastWin32:AceCrypter-U [Cryp]
TencentTrojan-Spy.Win32.Stealer.16000356
Ad-AwareTrojan.GenericKDZ.86263
SophosMal/Generic-S + Troj/Krypt-IR
ComodoMalware@#364ik1neg8j3
VIPRETrojan.GenericKDZ.86263
TrendMicroRansom.Win32.STOP.FP
McAfee-GW-EditionPacked-GDT!FA46D6D2450B
SentinelOneStatic AI – Suspicious PE
FireEyeGeneric.mg.fa46d6d2450b9eaf
EmsisoftTrojan.Crypt (A)
IkarusTrojan.Win32.Crypt
GDataWin32.Trojan.PSE.11759A6
JiangminBackdoor.Androm.bded
AviraTR/Agent.rdidsi
Antiy-AVLTrojan/Generic.ASMalwS.50E8
KingsoftWin32.Troj.Undef.(kcloud)
ZoneAlarmHEUR:Trojan.Win32.Strab.gen
MicrosoftRansom:Win32/StopCrypt.PBF!MTB
CynetMalicious (score: 100)
AhnLab-V3Packed/Win.GDT.R483294
VBA32BScope.Malware-Cryptor.Hlux
ALYacTrojan.GenericKDZ.86263
MalwarebytesTrojan.MalPack.GS
APEXMalicious
RisingTrojan.Kryptik!1.D977 (KTSE)
MAXmalware (ai score=100)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Packed.GDT!tr
AVGWin32:AceCrypter-U [Cryp]
PandaTrj/WLT.G
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom.StopcryptRI.S27595683?

Ransom.StopcryptRI.S27595683 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment