Ransom

Ransom:Win32/StopCrypt.PAD!MTB removal tips

Malware Removal

The Ransom:Win32/StopCrypt.PAD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/StopCrypt.PAD!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Manipuri
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Ransom:Win32/StopCrypt.PAD!MTB?


File Info:

name: 8BFB533EBBA795369B22.mlw
path: /opt/CAPEv2/storage/binaries/c1bd261f96669da2d90be7d8c15deb7a9d42e8e9e21535e0662febe86b4e008f
crc32: A94AB7AF
md5: 8bfb533ebba795369b22e357cf6c7104
sha1: 8852dc1774931678343fc65ca693466c8a44d0af
sha256: c1bd261f96669da2d90be7d8c15deb7a9d42e8e9e21535e0662febe86b4e008f
sha512: d2097bfc85da1519b27b7b26a52c383c47298540b78534970cf5f1e88672ea7ba32127fa0b4dcb7e6c0ed10505f4c15c42137c26fe99ed5008f86b3e973b9919
ssdeep: 3072:KeRnFixJbzLuJghIWqAfIujQQhsJVggjcGkNIVqIbM/h3:pIhIjukr7ITsq0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F5547CE17690DB71D4963A3088758FA05EBEFC01D960864B72B83BAE6F732C1562531F
sha3_384: b4aab0635577ea154633b2aa8873ee998c779242d96dddc7856b42f521ec5ec957e53d06454436ca13e4c74af0613a47
ep_bytes: e88e450000e978feffffcccccccccccc
timestamp: 2020-11-04 15:11:31

Version Info:

InternationalName: bomgvioci.iwa
Copyright: Copyrighz (C) 2021, fudkort
ProjectVersion: 3.14.72.77
Translation: 0x0129 0x07bc

Ransom:Win32/StopCrypt.PAD!MTB also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38385558
FireEyeGeneric.mg.8bfb533ebba79536
CAT-QuickHealTrojan.RaccryptPMF.S25803454
ALYacTrojan.GenericKD.38385558
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Kryptik.FWV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNWX
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Tofsee-9919472-0
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderTrojan.GenericKD.38385558
AvastWin32:BotX-gen [Trj]
Ad-AwareTrojan.GenericKD.38385558
SophosMal/Generic-S + Mal/Agent-AWV
DrWebTrojan.Siggen16.21468
TrendMicroTrojan.Win32.SMOKELOADER.YXBL5Z
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.dm
EmsisoftTrojan.GenericKD.38385558 (B)
IkarusTrojan.Win32.Krypt
GDataWin32.Trojan.BSE.16VOW5Z
JiangminTrojan.Agent.dttl
MAXmalware (ai score=83)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/StopCrypt.PAD!MTB
CynetMalicious (score: 100)
AhnLab-V3Infostealer/Win.SmokeLoader.R461425
McAfeeLockbit-FSWW!8BFB533EBBA7
VBA32Trojan.Sabsik.FL
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTrojan.Win32.SMOKELOADER.YXBL5Z
RisingTrojan.Raccrypt!8.12B71 (CLOUD)
YandexTrojan.Kryptik!bDELo364M+M
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_95%
FortinetW32/GenKryptik.ERHN!tr
BitDefenderThetaGen:NN.ZexaF.34160.suW@aiw1BKeK
AVGWin32:BotX-gen [Trj]
Cybereasonmalicious.774931
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Ransom:Win32/StopCrypt.PAD!MTB?

Ransom:Win32/StopCrypt.PAD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment