Ransom

Ransom:Win32/Stop.PA!MTB removal instruction

Malware Removal

The Ransom:Win32/Stop.PA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Stop.PA!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ransom:Win32/Stop.PA!MTB?


File Info:

crc32: CD3D9B5F
md5: 249b78e3ecc410a3f60d655bb8a735e8
name: 249B78E3ECC410A3F60D655BB8A735E8.mlw
sha1: f9b88c4845f64b3b00f126f934feb45746ddcab7
sha256: d597e6564525edf3f0fc8c023000a882df6593906b8d739ee4592f55d57a8e7e
sha512: 5c044d788763209f4d8fdffaea31ad8e4ba02c7122e031d9de3a261538cd281ea1dd9507a5bcded733edb42a1da63809237d57afd62c70b48daf10f074939d34
ssdeep: 6144:X8LLR41AWcDieQaFulU40sU/wI/iMQyvLIMieb0pYoHPEZkbfOo:sLLR41AWcDnZFuv0xiuJieRovEGm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Ssdfd (c) 2019
InternalName: sgsdfgds.exe
FileVersion: 1.0.0.1
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04e4

Ransom:Win32/Stop.PA!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005563f21 )
LionicHacktool.Win32.Nekto.3!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Sodinokibi
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaMalware:Win32/km_2c971.None
K7GWTrojan ( 005563f21 )
Cybereasonmalicious.3ecc41
CyrenW32/Kryptik.ABV.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GVQQ
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Generic-9853074-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusExploit.Win32.Nekto.fwnpua
MicroWorld-eScanTrojan.Brsecmon.1
TencentWin32.Trojan.Generic.Hqvr
Ad-AwareTrojan.Brsecmon.1
SophosMal/Generic-R + Mal/GandCrab-G
ComodoMalware@#1485vcvbcklpi
BitDefenderThetaGen:NN.ZexaF.34236.Cu0@aSOTW9iG
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.SODINOK.SM.hp
McAfee-GW-EditionBehavesLike.Win32.PUPXFM.gh
FireEyeGeneric.mg.249b78e3ecc410a3
EmsisoftTrojan.Brsecmon.1 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.SodinoRansom.hke
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan[Exploit]/Win32.Nekto
MicrosoftRansom:Win32/Stop.PA!MTB
ArcabitTrojan.Brsecmon.1
GDataTrojan.Brsecmon.1
AhnLab-V3Win-Trojan/MalPe24.Suspicious.X2009
Acronissuspicious
McAfeeTrojan-FRIF!249B78E3ECC4
MAXmalware (ai score=85)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
RisingTrojan.Generic@ML.95 (RDMK:Vg1mKNGzu7wiuO5B9GQcYQ)
IkarusTrojan-Ransom.Stop
MaxSecureTrojan.Malware.74517159.susgen
FortinetW32/Kryptik.HJCJ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom:Win32/Stop.PA!MTB?

Ransom:Win32/Stop.PA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment