Ransom

Ransom:Win32/StopCrypt.PAM!MTB removal guide

Malware Removal

The Ransom:Win32/StopCrypt.PAM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/StopCrypt.PAM!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Syriac
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • CAPE detected the Tofsee malware family
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/StopCrypt.PAM!MTB?


File Info:

name: A069ECD74B43F8824474.mlw
path: /opt/CAPEv2/storage/binaries/3aec2f7677eb0f463cd285886982edf88e6ec4b92b63b201ce668012d0502815
crc32: A55E0291
md5: a069ecd74b43f8824474d09e1985a4ac
sha1: 6eacbdb005d60373570c4e8deade2c5b32d0f570
sha256: 3aec2f7677eb0f463cd285886982edf88e6ec4b92b63b201ce668012d0502815
sha512: 09b72c182b2580e8c2608b7225ce76a5ac8e59da8d1805d556b1212b43ab9b09d41b3517c5e082930398a523e7b39d3b22044f8bf47cffe3b28bd2a167c42455
ssdeep: 24576:Tmplhzxzxzxzxzxzxzxzxzxzxzxzxzxzxzxzxzxzxzxzxzxzxzxzxzxzxzxzxzxn:yp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D1E66A34AFEDC549E5B787708B31FAD80A3ABC91F911625B1550E20A2D70EDC8DD236E
sha3_384: c41b5fe6bfb5a05e4046be588e84a2234bc667fbb783044e0f4af4b61bdd2de11d5eb086b7e12415656ed363a5860a05
ep_bytes: e8ba580000e978feffffcccccccccccc
timestamp: 2020-11-17 18:00:22

Version Info:

InternationalName: bomgvioci.iwa
Copyright: Copyrighz (C) 2021, fudkort
ProjectVersion: 3.10.70.17
Translation: 0x0129 0x0794

Ransom:Win32/StopCrypt.PAM!MTB also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.26952
MicroWorld-eScanTrojan.GenericKDZ.82239
FireEyeGeneric.mg.a069ecd74b43f882
CAT-QuickHealTrojan.IgenericPMF.S26103249
ALYacTrojan.GenericKDZ.82239
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058d1b01 )
K7GWTrojan ( 0058d1b01 )
Cybereasonmalicious.005d60
ArcabitTrojan.Generic.D1413F
BitDefenderThetaGen:NN.ZexaF.34182.@tW@ayMXxbpG
CyrenW32/Qbot.FK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNYT
TrendMicro-HouseCallMal_Tofsee
ClamAVWin.Trojan.Generic-9935605-0
KasperskyHEUR:Trojan-Ransom.Win32.Stop.gen
BitDefenderTrojan.GenericKDZ.82239
AvastWin32:AceCrypter-B [Cryp]
Ad-AwareTrojan.GenericKDZ.82239
EmsisoftTrojan.Crypt (A)
ZillyaTrojan.Kryptik.Win32.3667381
TrendMicroMal_Tofsee
McAfee-GW-EditionPacked-GEE!A069ECD74B43
SophosML/PE-A + Mal/Agent-AWV
IkarusTrojan.Win32.Crypt
JiangminTrojan.Stop.ctr
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftRansom:Win32/StopCrypt.PAM!MTB
ZoneAlarmHEUR:Trojan-Ransom.Win32.Stop.gen
GDataWin32.Trojan.BSE.16VOW5Z
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.MalPE.R464473
McAfeeGenericRXAA-AA!A069ECD74B43
VBA32BScope.TrojanSpy.Stealer
MalwarebytesTrojan.MalPack.GS
APEXMalicious
RisingTrojan.Kryptik!1.DB29 (RDMK:cmRtazqcRK5A1tPf6gQw8LLj9RLi)
YandexTrojan.Kryptik!6bEg7JoPudU
MAXmalware (ai score=88)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.ERHN!tr
AVGWin32:AceCrypter-B [Cryp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Ransom:Win32/StopCrypt.PAM!MTB?

Ransom:Win32/StopCrypt.PAM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment