Ransom

Ransom:Win32/StopCrypt.TA!MTB malicious file

Malware Removal

The Ransom:Win32/StopCrypt.TA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/StopCrypt.TA!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Tswana
  • Authenticode signature is invalid
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Ransom:Win32/StopCrypt.TA!MTB?


File Info:

name: D8D0D4C8EB2F10A8691E.mlw
path: /opt/CAPEv2/storage/binaries/cf310769fea332a5e5ad27af3b6244020e826f8bc989675484945bd76e103159
crc32: 8A4EF1E1
md5: d8d0d4c8eb2f10a8691e45261bc56252
sha1: 19f33b75bcf842f107d841a6cab94b0eb6b3a41b
sha256: cf310769fea332a5e5ad27af3b6244020e826f8bc989675484945bd76e103159
sha512: 4520486e41ed0a460cacf123776bc95a002677f91275ee68fcac4b6567e9043c6637f48295ab49a24beffaa850269b48acae71e0f86f4771526f62c6381da501
ssdeep: 3072:OYL5IiiQ8FAT5bGY6FnG+jliSKpfsSvcjz/PZe4nqBDLnjxX:ZKiqitGlG3f1vc3P1qVLR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DE54D0227BA0C072C09255744124D7E25A7BBC3227E589B777A4276E1F307E1BB7A347
sha3_384: 31c663ea2e4e2e5bdf107d4bd60497fd3a05cda9182e71c07e9f793919f7c763e3808ff9cec947030c35ab8adcd0da8c
ep_bytes: e8866c0000e978feffff8bff558bec8b
timestamp: 2021-10-12 07:24:00

Version Info:

FileVersions: 68.52.46.13
InternationalName: povgwaoci.iwe
Copyright: Copyright (C) 2022, somoklos
ProjectsVersion: 75.0.48.6

Ransom:Win32/StopCrypt.TA!MTB also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.63448782
FireEyeGeneric.mg.d8d0d4c8eb2f10a8
McAfeeArtemis!D8D0D4C8EB2F
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0059a7551 )
K7GWTrojan ( 0059a7551 )
Cybereasonmalicious.5bcf84
CyrenW32/Kryptik.HUW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HRLM
TrendMicro-HouseCallTrojan.Win32.PRIVATELOADER.YXCKFZ
Paloaltogeneric.ml
ClamAVWin.Packed.Botx-9976898-0
KasperskyHEUR:Trojan.Win32.Packed.gen
BitDefenderTrojan.GenericKD.63448782
CynetMalicious (score: 100)
APEXMalicious
TencentWin32.Trojan.Packed.Ocnw
Ad-AwareTrojan.GenericKD.63448782
SophosMal/Generic-S + Troj/Krypt-RQ
ComodoMalware@#23yuzwsoum9uq
DrWebTrojan.Siggen19.3493
TrendMicroTrojan.Win32.PRIVATELOADER.YXCKFZ
McAfee-GW-EditionBehavesLike.Win32.Lockbit.dm
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.63448782 (B)
IkarusTrojan.Win32.Crypt
GDataTrojan.GenericKD.63448782
Antiy-AVLTrojan/Generic.ASMalwS.631F
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D3C826CE
MicrosoftRansom:Win32/StopCrypt.TA!MTB
GoogleDetected
AhnLab-V3Dropper/Win.DropperX-gen.R533338
Acronissuspicious
VBA32BScope.TrojanDownloader.Ajent
ALYacTrojan.GenericKD.63448782
MalwarebytesTrojan.MalPack.GS
AvastWin32:DropperX-gen [Drp]
RisingTrojan.Generic@AI.100 (RDML:esAkOhLTAewEt0YJkCx6KQ)
FortinetW32/GenKryptik.ETEM!tr
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A

How to remove Ransom:Win32/StopCrypt.TA!MTB?

Ransom:Win32/StopCrypt.TA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment