Ransom

Ransom:Win32/StopCrypt.SL!MTB removal instruction

Malware Removal

The Ransom:Win32/StopCrypt.SL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/StopCrypt.SL!MTB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com

How to determine Ransom:Win32/StopCrypt.SL!MTB?


File Info:

crc32: 000E7EAE
md5: 8346b2653645fb89d1e39547e00f74ce
name: 8346B2653645FB89D1E39547E00F74CE.mlw
sha1: 315d6cdc4284ef78e064ed797648a8b87eb7a1c4
sha256: 041db87bc4477d22b3fa90613ace50f7bfd70e248a6f396e8d12b09e982541af
sha512: 5d9bbf60b5fca8ec31893f9fd02baa51ed78322b2245bd38eac9a77d23945cec7f56e2a6753c53116db1c34580264392accf25aba51a40b857f3fae8a9762fac
ssdeep: 6144:43URMIrpUUbgwXLlg3OLWEvnexSyKt9Zundpd3p74ScPnEp7oO1W+5OobsI5/:+IVUWgKg+LWAdvcP4S0EpZW+Ic
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sagzmioloku.aci
ProductVersion: 7.59.25.123
Copyright: Copyrighz (C) 2021, fudkageta
Translation: 0x0183 0x022e

Ransom:Win32/StopCrypt.SL!MTB also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0056f9be1 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader41.33734
CynetMalicious (score: 100)
ALYacTrojan.Agent.Raccoon
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Kryptik.c342150b
K7GWTrojan ( 0056f9be1 )
CyrenW32/Kryptik.EWJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMGA
APEXMalicious
AvastFileRepMalware
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Fragtor.12051
MicroWorld-eScanGen:Variant.Fragtor.12051
Ad-AwareGen:Variant.Fragtor.12051
SophosMal/Generic-R + Troj/Krypt-BO
BitDefenderThetaGen:NN.ZexaF.34110.Aq0@aKeZ@HaG
TrendMicroMal_HPGen-50
McAfee-GW-EditionBehavesLike.Win32.Emotet.gc
FireEyeGeneric.mg.8346b2653645fb89
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_74%
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/StopCrypt.SL!MTB
GridinsoftTrojan.Win32.Packed.lu!heur
ArcabitTrojan.Fragtor.D2F13
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Fragtor.12051
AhnLab-V3Infostealer/Win.SmokeLoader.R439013
Acronissuspicious
McAfeeGenericRXAA-AA!8346B2653645
MAXmalware (ai score=85)
VBA32BScope.TrojanRansom.Blocker
MalwarebytesMachineLearning/Anomalous.96%
TrendMicro-HouseCallMal_HPGen-50
RisingTrojan.Kryptik!1.D8AC (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HMFT!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Ransom:Win32/StopCrypt.SL!MTB?

Ransom:Win32/StopCrypt.SL!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment