Ransom

Should I remove “Ransom:Win32/StopCrypt.MNK!MTB”?

Malware Removal

The Ransom:Win32/StopCrypt.MNK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/StopCrypt.MNK!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Spanish (Paraguay)
  • The binary likely contains encrypted or compressed data.

Related domains:

z.whorecord.xyz
a.tomx.xyz
telegatt.top
telegka.top

How to determine Ransom:Win32/StopCrypt.MNK!MTB?


File Info:

crc32: 94B2CB39
md5: 7d35e4a38d78a4d361b51a3b3e6a6e8a
name: 7D35E4A38D78A4D361B51A3B3E6A6E8A.mlw
sha1: 2b42aded17ecbfc832909f1a42c557258904ab37
sha256: 665044e68300e3da42a2dbbf0a64861290e50503a47b32b11a36d7e0b3dee594
sha512: fcc1f0e030eaead973e600f5fd81d07d1f77178b290521b209fd3dc5b908c2075578ff9f73370f28e768e8c9ef54fa9173223dfd9176953a60b06bc78a012f59
ssdeep: 12288:9ZYwCxff3Agx1kTmGZ83uuVMnSwLayqURders2TTap3ySaNuF:9ZYwUff3omGZ83LOnjLKUgTTap6o
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0152 0x0011

Ransom:Win32/StopCrypt.MNK!MTB also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.30912019
CAT-QuickHealRansom.Stop.Z5
ALYacTrojan.Generic.30912019
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.d17ecb
BaiduWin32.Trojan.Kryptik.jm
CyrenW32/Kryptik.FNY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMYN
APEXMalicious
AvastWin32:BotX-gen [Trj]
ClamAVWin.Trojan.Raccoon-9903173-1
AlibabaRansom:Win32/StopCrypt.101835a0
Ad-AwareTrojan.Generic.30912019
SophosMal/Generic-R + Troj/Krypt-DI
ComodoMalware@#xx3w1y151cxc
TrendMicroTROJ_FRS.0NA103JI21
FireEyeGeneric.mg.7d35e4a38d78a4d3
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
JiangminExploit.ShellCode.ffl
AviraTR/Crypt.Agent.cxovg
Antiy-AVLTrojan/Generic.ASMalwS.34BE783
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D1D7AE13
MicrosoftRansom:Win32/StopCrypt.MNK!MTB
AhnLab-V3Packed/Win.GDV.R446115
Acronissuspicious
McAfeePacked-GDT!7D35E4A38D78
MAXmalware (ai score=80)
VBA32Trojan.Sabsik.FL
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FRS.0NA103JI21
TencentWin32.Exploit.Shellcode.Aisb
YandexTrojan.Kryptik!53wIPrpKP0Y
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HMYN!tr
AVGWin32:BotX-gen [Trj]
Paloaltogeneric.ml

How to remove Ransom:Win32/StopCrypt.MNK!MTB?

Ransom:Win32/StopCrypt.MNK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment