Ransom

Ransom:Win32/StopCrypt.PAS!MTB removal instruction

Malware Removal

The Ransom:Win32/StopCrypt.PAS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/StopCrypt.PAS!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Macedonian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Transacted Hollowing
  • Created a process from a suspicious location
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • STOP ransomware registry artifacts detected
  • CAPE detected the STOP malware family
  • Attempts to modify proxy settings
  • Creates a known STOP ransomware variant mutex
  • STOP ransomware command line behavior detected
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/StopCrypt.PAS!MTB?


File Info:

name: 7B847F172A80BE2FB32F.mlw
path: /opt/CAPEv2/storage/binaries/09fade8e175f98fee0571b6405ce0209854b3e2a22ded3980be17bf3112520e0
crc32: 7EBB910F
md5: 7b847f172a80be2fb32f5f29e2afa792
sha1: a7b9606249bfc0a32831bc6769c951bff8f27598
sha256: 09fade8e175f98fee0571b6405ce0209854b3e2a22ded3980be17bf3112520e0
sha512: 9301f0fa0856356ca35827b523fcc9f95f2700967932bb1c374d164b18e44f2cfa9d84a199581b711eb86289c0e54a5cfae136e3d2e04f342beb99e8ec08a8ec
ssdeep: 12288:rSeysgoiuRZX7CWE78nFXRDvLsYUpFQcDRUNu30ecqf/1Ic4v2S74hLs6:rSey8i+Z2WE78nFXhLRPctaqn1Ifv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DBF4120172C0C072D5A626B64879C7B14ABB7C665936AF9F7AC512FD0F253E2CF26342
sha3_384: 227212dcbf14ad61cda50cb53c73d00ddb56d63fb58ad245808bc388dcca27de0a0a32a15bf615f3ca86bb8a97a5911a
ep_bytes: e815450000e978feffff8bff558bec81
timestamp: 2020-09-04 13:03:46

Version Info:

FileVers: 65.51.36.16
ProductVersa: 7.50.25.71
InternalName: peatemas
LegalCopyrighd: sharmir
Translation: 0x0169 0x0300

Ransom:Win32/StopCrypt.PAS!MTB also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Scarsi.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.83189
CAT-QuickHealRansom.Stop.P5
ALYacTrojan.Ransom.Stop
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058d91f1 )
AlibabaRansom:Win32/StopCrypt.4c0f23f8
K7GWTrojan ( 0058d91f1 )
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/Kryptik.GDH.gen!Eldorado
SymantecPacked.Generic.620
ESET-NOD32a variant of Win32/Kryptik.HODV
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-9937750-0
KasperskyHEUR:Trojan.Win32.Scarsi.gen
BitDefenderTrojan.GenericKDZ.83189
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Scarsi.Ajvo
EmsisoftTrojan.GenericKDZ.83189 (B)
TrendMicroRansom_StopCrypt.R002C0DAV22
McAfee-GW-EditionBehavesLike.Win32.SoftPulse.bc
FireEyeGeneric.mg.7b847f172a80be2f
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
AviraTR/AD.InstaBot.bffyn
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.351CE63
GridinsoftRansom.Win32.STOP.sa
MicrosoftRansom:Win32/StopCrypt.PAS!MTB
ZoneAlarmHEUR:Trojan.Win32.Scarsi.gen
GDataTrojan.GenericKDZ.83189
CynetMalicious (score: 100)
AhnLab-V3Ransomware/Win.Stop.R468727
McAfeePacked-GBE!7B847F172A80
VBA32Malware-Cryptor.2LA.gen
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallRansom_StopCrypt.R002C0DAV22
RisingBackdoor.Tofsee!8.1E9 (TFE:dGZlOgXNI1/SdesWgA)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.73857037.susgen
FortinetW32/GenKryptik.FQFQ!tr
BitDefenderThetaGen:NN.ZexaF.34182.Uq0@aKxizbiG
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.249bfc
PandaTrj/GdSda.A

How to remove Ransom:Win32/StopCrypt.PAS!MTB?

Ransom:Win32/StopCrypt.PAS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment