Ransom

Ransom:Win32/StopCrypt!MSR removal tips

Malware Removal

The Ransom:Win32/StopCrypt!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/StopCrypt!MSR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks for the presence of known windows from debuggers and forensic tools
  • Created a process from a suspicious location
  • Steals private information from local Internet browsers
  • CAPE detected the DLInjector03 malware family
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Attempts to disable Windows Defender

How to determine Ransom:Win32/StopCrypt!MSR?


File Info:

name: 2A0A05BCAE0114F54320.mlw
path: /opt/CAPEv2/storage/binaries/d74a07eeb26faeed4799f582bcb3c22ba985cc7bf21685d3b6e37aa694a72d97
crc32: 8F654ED7
md5: 2a0a05bcae0114f543206ed1a81a8c69
sha1: 0e6b17c5c3dcab55697b4589e8a239961fac9ed0
sha256: d74a07eeb26faeed4799f582bcb3c22ba985cc7bf21685d3b6e37aa694a72d97
sha512: 5aaee090fc713af1add2a040bb6cfdde26650c6991249d7cfe94bfdb04e5a9a65f2ede7db317a2eb67e0763a097c997612fbef2c9829053e81bb6d9afe97f9cb
ssdeep: 49152:xcBECpZgu2Wk+EwJ84vLRaBtIl9mTXcRjt0S:xaZ2WOCvLUBsKsFt0S
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11D7523717BE1C5B9D5406131AA8C2F7250FDC35E0B3116EB77D4C70EAF3C8929226A6A
sha3_384: 9652ec437b9c2061ff51fed99992e64570d6513beb5563df20fef170f7e8fc7492bef4128dd66cd2ae6a84b205012920
ep_bytes: 558bec6aff6898c24100680691410064
timestamp: 2019-02-21 16:00:00

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Setup SFX
FileVersion: 19.00
InternalName: 7zS.sfx
LegalCopyright: Copyright (c) 1999-2018 Igor Pavlov
OriginalFilename: 7zS.sfx.exe
ProductName: 7-Zip
ProductVersion: 19.00
Translation: 0x0409 0x04b0

Ransom:Win32/StopCrypt!MSR also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agentb.4!c
MicroWorld-eScanTrojan.AgentWDCR.ACQM
FireEyeTrojan.AgentWDCR.ACQM
CAT-QuickHealTrojan.PE_EXE
ALYacTrojan.AgentWDCR.ACQM
CylanceUnsafe
SangforTrojan.Win32.Sdum.gen
K7AntiVirusTrojan ( 0057f9a81 )
AlibabaRansom:Win32/StopCrypt.0fd3664f
K7GWTrojan ( 0057f9a81 )
CyrenW32/Kryptik.EYC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Smokeloader.F
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Barys-9859531-0
KasperskyTrojan.Win32.Agentb.kmqd
BitDefenderTrojan.AgentWDCR.ACQM
NANO-AntivirusTrojan.Win32.TrjGen.ixvlyj
AvastWin32:PWSX-gen [Trj]
RisingTrojan.Kryptik!1.C6FC (CLASSIC)
Ad-AwareTrojan.AgentWDCR.ACQM
SophosMal/Generic-S + Mal/Generic-L
ComodoMalware@#1hum2f7668mcr
DrWebTrojan.Siggen14.45875
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.QAKBOT.TIAOABEP
McAfee-GW-EditionRDN/Generic.grp
EmsisoftTrojan.AgentWDCR.ACQM (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.Agent.POBWZK
JiangminTrojan.Sdum.rm
AviraTR/Agent.ghrg
Antiy-AVLTrojan/Generic.ASMalwS.3452F82
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.AgentWDCR.ACQM
MicrosoftRansom:Win32/StopCrypt!MSR
CynetMalicious (score: 100)
AhnLab-V3Ransomware/Win.StopCrypt.C4572370
McAfeeArtemis!2A0A05BCAE01
MAXmalware (ai score=85)
VBA32BScope.Adware.SpeedBit
MalwarebytesMalware.AI.684285136
TrendMicro-HouseCallTrojanSpy.Win32.QAKBOT.TIAOABEP
TencentWin32.Trojan.Agentb.Hpsc
YandexTrojan.Chapak!RS2nZZWtDPQ
IkarusTrojan.Win32.Agent
eGambitUnsafe.AI_Score_99%
FortinetW32/Chapak.ADHQ!tr
BitDefenderThetaGen:NN.ZexaF.34062.cv0@aqgz2qiO
AVGWin32:PWSX-gen [Trj]
PandaTrj/WLT.G
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.73643692.susgen

How to remove Ransom:Win32/StopCrypt!MSR?

Ransom:Win32/StopCrypt!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment