Ransom

Ransom:Win32/StopCrypt.PC!MTB removal instruction

Malware Removal

The Ransom:Win32/StopCrypt.PC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/StopCrypt.PC!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Arabic (Libya)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Anomalous binary characteristics

How to determine Ransom:Win32/StopCrypt.PC!MTB?


File Info:

name: CC13F09402C25EECF806.mlw
path: /opt/CAPEv2/storage/binaries/af297257e7d61fc32d4933a0b7dbfd4cf20c23071ae9d2243f9db3bee0ecddf0
crc32: 43F9F274
md5: cc13f09402c25eecf806048c8ee0f393
sha1: 16b018f9eeb0e412f2e02c80f086e45740e71652
sha256: af297257e7d61fc32d4933a0b7dbfd4cf20c23071ae9d2243f9db3bee0ecddf0
sha512: ce4ff3ee6e833fd4494adc39adf463c63ec294b2e176f0e6b896b8df5ab3c5dd3d3ec25220a71cf84bbe585804768c80c0e1bc5204c6416f473deba84eec91cd
ssdeep: 6144:WOTsyeZKwPeOPPAtM+Tk37ybXvW6si/wAT9PkCBwjtwrsu:3TsyUmtMGk+b7s5AhFBairsu
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1E174E0113AA0CE32CAA709319720D7A46676B9626D34C7C77757AB7EEF203C27635306
sha3_384: 862731f9874286c3a54d4ff768cb89ce064b44ad6e8c1e5b272fe2856f795d25ab3210c1a21c34da519fc6024f8e5a5a
ep_bytes: e8bf440000e978feffffcccccccccccc
timestamp: 2020-09-25 20:47:23

Version Info:

InternalName: sojbmoeminu.ihe
Copyright: Copyrighz (C) 2021, fudkagata
ProductVersion: 8.19.590.38
Translation: 0x0129 0x0171

Ransom:Win32/StopCrypt.PC!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.37616465
FireEyeGeneric.mg.cc13f09402c25eec
McAfeeLockbit-FSWW!CC13F09402C2
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005894161 )
BitDefenderTrojan.GenericKD.37616465
K7GWTrojan ( 004d378c1 )
Cybereasonmalicious.9eeb0e
CyrenW32/Kryptik.EWJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.DZIC
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
AlibabaRansom:Win32/StopCrypt.544c62a8
RisingTrojan.Kryptik!1.D9B3 (CLOUD)
Ad-AwareTrojan.GenericKD.37616465
EmsisoftTrojan.GenericKD.37616465 (B)
ComodoMalware@#1qfjnn8bcvapm
ZillyaTrojan.Kryptik.Win32.3633033
TrendMicroTROJ_GEN.R03FC0DIO21
McAfee-GW-EditionLockbit-FSWW!CC13F09402C2
SophosMal/Generic-S + Troj/Krypt-BO
IkarusTrojan.Win32.Crypt
JiangminTrojanSpy.Stealer.fkq
eGambitPE.Heur.InvalidSig
AviraHEUR/AGEN.1145621
Antiy-AVLTrojan/Generic.ASMalwS.34AC3FB
MicrosoftRansom:Win32/StopCrypt.PC!MTB
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
GDataTrojan.GenericKD.37616465
AhnLab-V3Trojan/Win.Racealer.R442291
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34160.uq2@a0m5bjnO
ALYacTrojan.GenericKD.37616465
MAXmalware (ai score=89)
VBA32Trojan.Racealer
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R03FC0DIO21
YandexTrojan.DL.Phpw!6dQOTEJebAc
SentinelOneStatic AI – Suspicious PE
FortinetW32/Packed.GDV!tr
WebrootW32.Trojan.Gen
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Ransom:Win32/StopCrypt.PC!MTB?

Ransom:Win32/StopCrypt.PC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment