Ransom

About “Ransom:Win32/StopCrypt.PBD!MTB” infection

Malware Removal

The Ransom:Win32/StopCrypt.PBD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/StopCrypt.PBD!MTB virus can do?

  • Unconventionial language used in binary resources: Uzbek (Latin)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ransom:Win32/StopCrypt.PBD!MTB?


File Info:

name: 620837FE1D520B855C37.mlw
path: /opt/CAPEv2/storage/binaries/2c5268cdd29f95e4794331e5a97ec4b25c1609407c94d0189ea1fbfbbe86244c
crc32: 01B3D7F0
md5: 620837fe1d520b855c37f885ac76e40c
sha1: 4ea14e6ed3086bc38dbfc2a5e305dbed38afdfcf
sha256: 2c5268cdd29f95e4794331e5a97ec4b25c1609407c94d0189ea1fbfbbe86244c
sha512: 7c424cfeec3e997087ab61f8f1e13ccfc567121b22873cb7c853e0d2a20588423294d05b9b2cb354828d3341ff77ac0dca1eaaedb212eacad78f0e6ba61e21d7
ssdeep: 12288:G3+lB/Z2zL7g+0ZMzwi7777777777777777777777777P:GWo8+XT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15225AE4073D1EC66E3B195B04939A3F4253AB872972A66CB27483E4B7C32391EE71753
sha3_384: ad02abab4ea6b0e92bb3abb2398af09a262048294cafef9ea9e09b746065eb88fb676fc82785d08fb94004f6f5478223
ep_bytes: 8bff558bece8c6920000e8110000005d
timestamp: 2021-06-03 15:24:55

Version Info:

Translations: 0x0027 0x0306

Ransom:Win32/StopCrypt.PBD!MTB also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader44.48156
CynetMalicious (score: 100)
FireEyeGeneric.mg.620837fe1d520b85
CAT-QuickHealRansom.StopcryptPMF.S27330451
ALYacGen:Heur.Mint.Zard.52
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 005903821 )
K7AntiVirusTrojan ( 005903821 )
CyrenW32/Kryptik.GIY.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HPBK
ClamAVWin.Packed.Ransomx-9942692-0
BitDefenderGen:Heur.Mint.Zard.52
MicroWorld-eScanGen:Heur.Mint.Zard.52
TencentTrojan-Ransom.Win32.Stop.16000389
Ad-AwareGen:Heur.Mint.Zard.52
EmsisoftTrojan.Crypt (A)
ZillyaTrojan.Kryptik.Win32.3729668
McAfee-GW-EditionBehavesLike.Win32.Generic.th
SophosML/PE-A + Troj/Krypt-FV
IkarusTrojan.Win32.Crypt
GDataWin32.Trojan.PSE.1DYKG7E
JiangminBackdoor.Tofsee.fpa
ArcabitTrojan.Mint.Zard.52
MicrosoftRansom:Win32/StopCrypt.PBD!MTB
SentinelOneStatic AI – Malicious PE
AhnLab-V3Packed/Win.GEE.R481237
Acronissuspicious
McAfeePacked-GEE!620837FE1D52
VBA32TrojanSpy.Stealer
MalwarebytesMalware.AI.2754436744
APEXMalicious
RisingMalware.Obscure!1.A3BB (C64:YzY0Ovp/LwnkEaJq)
YandexTrojan.Kryptik!qNX5xizix+g
MAXmalware (ai score=88)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenericKDZ.DAED!tr
Cybereasonmalicious.ed3086
PandaTrj/Genetic.gen

How to remove Ransom:Win32/StopCrypt.PBD!MTB?

Ransom:Win32/StopCrypt.PBD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment