Ransom

Ransom:Win32/StopCrypt.KS!MTB removal guide

Malware Removal

The Ransom:Win32/StopCrypt.KS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/StopCrypt.KS!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Saami
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Accessed credential storage registry keys
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Ransom:Win32/StopCrypt.KS!MTB?


File Info:

name: 4A4F1AE2232ADFCA73B1.mlw
path: /opt/CAPEv2/storage/binaries/a7032f8b9aea271601db6674a9e4c43dfd0d7625dea6da8294768e7fdfce90de
crc32: 93E92B86
md5: 4a4f1ae2232adfca73b1ee2dcc114ad3
sha1: 38f9ff0612971ae67a218c692613118defd55316
sha256: a7032f8b9aea271601db6674a9e4c43dfd0d7625dea6da8294768e7fdfce90de
sha512: 8ea9dd373c94e79732990bd7f30c5ef8425f9826bdaaa465716ee89cf370c10dfe2f0b39b539c7d5d9da513bf85a7aee1d1eadb3d11c1ca355a2d69cdb81da93
ssdeep: 98304:Ia3inGKt/6ZpALsWXm8odTyyYqR3xqmOW:z6/6Iy8oYuYpW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14C16334332907CA5F6235F325F2E86E96B0EFC804E9473DA2A191E1F4D7067AD623716
sha3_384: 433c8420948be60a7f33ec049443d128717a5c10e1f86ef6d7a9bfe81402eb6b4b63b6a59bec1db6e4ada1e738eb4f24
ep_bytes: e8293a0000e989feffffff350c538100
timestamp: 2023-03-12 03:53:19

Version Info:

FileDescriptions: Nuts
InternalName: Buckiyarn.exe
LegalTrademark1: Gurumess
LegalTrademarks2: Gunshutting
OriginalFilename: Buskebaser.exe
ProductVersion: 76.47.92.28
Translation: 0x0709 0x04e2

Ransom:Win32/StopCrypt.KS!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Windigo.l!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.70271945
SkyhighArtemis!Trojan
McAfeeGenericRXWL-IR!4A4F1AE2232A
MalwarebytesTrojan.MalPack.GS
SangforTrojan.Win32.Save.a
BitDefenderTrojan.GenericKD.70271945
Cybereasonmalicious.612971
SymantecML.Attribute.HighConfidence
ElasticWindows.Trojan.Smokeloader
ESET-NOD32a variant of Win32/Kryptik.HVEQ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Dropper.Tofsee-10013797-0
KasperskyHEUR:Trojan-Spy.Win32.Windigo.gen
AlibabaRansom:Win32/StopCrypt.50f00ff9
ViRobotTrojan.Win.Z.Windigo.4348792
RisingTrojan.Generic@AI.94 (RDML:R+eiz+CxVtjXQOsuweoa8g)
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1305378
DrWebTrojan.PackedENT.147
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.4a4f1ae2232adfca
EmsisoftTrojan.GenericKD.70271945 (B)
IkarusTrojan-Ransom.StopCrypt
WebrootW32.Windigo
VaristW32/Kryptik.LAE.gen!Eldorado
AviraHEUR/AGEN.1305378
Kingsoftmalware.kb.a.998
MicrosoftRansom:Win32/StopCrypt.KS!MTB
GridinsoftTrojan.Win32.Glupteba.bot
ArcabitTrojan.Generic.D43043C9
ZoneAlarmHEUR:Trojan-Spy.Win32.Windigo.gen
GDataTrojan.GenericKD.70271945
GoogleDetected
AhnLab-V3Trojan/Win.Amadey.R611968
MAXmalware (ai score=81)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R06CH07K723
TencentTrojan.Win32.Obfuscated.gen
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.HVEG!tr
AVGWin32:BotX-gen [Trj]
AvastWin32:BotX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom:Win32/StopCrypt.KS!MTB?

Ransom:Win32/StopCrypt.KS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment