Ransom

Ransom:Win32/StopCrypt.PL!MTB malicious file

Malware Removal

The Ransom:Win32/StopCrypt.PL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/StopCrypt.PL!MTB virus can do?

  • Unconventionial language used in binary resources: Bulgarian
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Ransom:Win32/StopCrypt.PL!MTB?


File Info:

crc32: 1A7C7DC2
md5: 9126423ee23da915f7fdc34f1b69e55f
name: 9126423EE23DA915F7FDC34F1B69E55F.mlw
sha1: 16eff581f3d87e1e44b0e933982b1c5bf24a8236
sha256: da1733f57f5910ff234bef4cf0b3ab4e82baf8e98855c702161c9f2564fa6bef
sha512: 7f563cd55b7d10893a42d906fbf7aa1d11006e9108f3852bb2d47f4550cd53d29a3bee27b11b24d0eca0a0723e84077ca5af74116aeb9c8b193a20dfcc4e6317
ssdeep: 12288:Skprzfggjfh091x5Ug05mg2nAvy2X6gkV/YvwZGEX8c:SqHgWZ091og0k2XLE/jsE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: natgpiamizu.iwa
ProductVersion: 91.40.21.87
Copyright: Copyrighz (C) 2021, fudkagat
Translation: 0x0196 0x03fd

Ransom:Win32/StopCrypt.PL!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0056d16b1 )
LionicTrojan.Win32.Convagent.m!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Spy.21580
ClamAVWin.Trojan.Generic-9903365-0
ALYacTrojan.GenericKD.47215896
MalwarebytesTrojan.MalPack.GS
ZillyaTrojan.Kryptik.Win32.3579397
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0056d16b1 )
Cybereasonmalicious.1f3d87
CyrenW32/StopCrypt.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMZJ
APEXMalicious
AvastWin32:BotX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Exploit.Win32.ShellCode.gen
BitDefenderTrojan.GenericKD.47215896
MicroWorld-eScanTrojan.GenericKD.47215896
Ad-AwareTrojan.GenericKD.47215896
SophosML/PE-A + Troj/Krypt-BO
BitDefenderThetaGen:NN.ZexaF.34236.Gy0@aqLdn5aG
TrendMicroRansom_StopCrypt.R002C0DJN21
McAfee-GW-EditionBehavesLike.Win32.Lockbit.hc
FireEyeGeneric.mg.9126423ee23da915
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
JiangminExploit.ShellCode.fgx
AviraTR/AD.StellarStealer.citbz
eGambitUnsafe.AI_Score_95%
Antiy-AVLTrojan/Generic.ASMalwS.34BD554
MicrosoftRansom:Win32/StopCrypt.PL!MTB
GDataWin32.Trojan-Stealer.Racealer.3B5I1H
AhnLab-V3Packed/Win.GDV.R446483
Acronissuspicious
McAfeePacked-GDV!9126423EE23D
MAXmalware (ai score=81)
VBA32Trojan.Sabsik.FL
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_StopCrypt.R002C0DJN21
RisingTrojan.Kryptik!1.DA21 (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:BotX-gen [Trj]
Paloaltogeneric.ml

How to remove Ransom:Win32/StopCrypt.PL!MTB?

Ransom:Win32/StopCrypt.PL!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment