Ransom

Ransom:Win32/StopCrypt.SM!MTB removal instruction

Malware Removal

The Ransom:Win32/StopCrypt.SM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/StopCrypt.SM!MTB virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ransom:Win32/StopCrypt.SM!MTB?


File Info:

name: AC2DD32A84D0B080A963.mlw
path: /opt/CAPEv2/storage/binaries/a119abb5ae783275c3706c87cc8e868e4e5e0a85f82345dd1e1045ae7cadf40a
crc32: DC332314
md5: ac2dd32a84d0b080a963801533164f1b
sha1: 30e0345aafbdd310c262bd590ef3a4adb1571fa5
sha256: a119abb5ae783275c3706c87cc8e868e4e5e0a85f82345dd1e1045ae7cadf40a
sha512: 796c21687e9a2a39867564a6d728f0028fe726855380a71af55e75ce215bc97f3f41eae008697531d7b1019d877e8adf896f74a6d47e2a741e4efcbf650ef114
ssdeep: 384:OntOtDRZm7bjEGXS7v1i4idNe4jFjDxkKOn0AkUJ:OntOtDOQGkNPsljF3x/W0A1J
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T122726D135250C9B5E722B9309E442AF4D3FDD2765439CE0097284A25AF72AC7B83739E
sha3_384: 72e7496df3749202827039ed32c69bb0a6b8757836e5bc61e6716027519057db68b058e8c14285f6c31c82e211f3a278
ep_bytes:
timestamp: 2019-06-26 20:13:57

Version Info:

0: [No Data]

Ransom:Win32/StopCrypt.SM!MTB also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/StopCrypt.d77150e7
SymantecTrojan.Gen.MBT
ComodoHeur.Corrupt.PE@1z141z3
DrWebTrojan.Siggen9.62328
MicrosoftRansom:Win32/StopCrypt.SM!MTB
APEXMalicious
RisingTrojan.Kryptik!1.C98B (CLOUD)
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%

How to remove Ransom:Win32/StopCrypt.SM!MTB?

Ransom:Win32/StopCrypt.SM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment