Ransom

Ransom:Win32/STOP removal instruction

Malware Removal

The Ransom:Win32/STOP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/STOP virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.uguu.se
a.tomx.xyz

How to determine Ransom:Win32/STOP?


File Info:

crc32: 16DBD7A0
md5: 290dd01735994cf571a05b7a021d37e0
name: 290DD01735994CF571A05B7A021D37E0.mlw
sha1: 6d2ecd68dd15e43fcb8f7cb4013d05f33576ebe3
sha256: 02ecba68cbccd91522154fb63d7e12a114307b45c1426b8beb73a9232f02f9ca
sha512: 77589c02fd0743448f599a3d26709b08d2d4d22cb5f8ca79027218d7188218695844b26386702396692c3d4f82cc61dafde3b991db71c40dbba95296f3c8ec8f
ssdeep: 6144:54XrK9PX7Fp6Gh2wWRGl0EDDf1PisZQ5rAGQwg1QtP1f4paaYlsdcaMJEdbI0Pz:KXe9PPlowWX0t6mOQwg1Qd15CcYk0We
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0809 0x04b0

Ransom:Win32/STOP also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan-Downloader ( 0058178f1 )
LionicTrojan.Win32.Androm.m!c
Elasticmalicious (high confidence)
McAfeeRDN/Generic BackDoor
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Androm.70276754
K7GWTrojan-Downloader ( 0058178f1 )
Cybereasonmalicious.8dd15e
CyrenW32/Trojan.CTQD-8474
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDownloader.Autoit.PEM
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Androm.utgb
BitDefenderTrojan.GenericKD.46874632
NANO-AntivirusTrojan.Win32.Androm.izqolr
MicroWorld-eScanTrojan.GenericKD.46874632
TencentMalware.Win32.Gencirc.10cecbe6
Ad-AwareTrojan.GenericKD.46874632
SophosMal/Generic-S
TrendMicroTROJ_FRS.VSNW1BH21
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.fc
FireEyeGeneric.mg.290dd01735994cf5
EmsisoftTrojan.GenericKD.46874632 (B)
WebrootW32.Trojan.GenKD
AviraTR/Dldr.Autoit.aexev
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/STOP
GDataWin32.Trojan.PSE.JCXCHA
AhnLab-V3Trojan/Win.Generic.C4609845
VBA32Backdoor.Androm
MAXmalware (ai score=82)
MalwarebytesTrojan.Downloader
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_FRS.VSNW1BH21
YandexTrojan.Igent.bWtRgN.46
IkarusTrojan.Inject
MaxSecureTrojan.Malware.120919011.susgen
FortinetAutoIt/Injector.BFC6!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Ransom:Win32/STOP?

Ransom:Win32/STOP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment