Ransom Trojan

Trojan.Ransom.Stop (file analysis)

Malware Removal

The Trojan.Ransom.Stop is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.Stop virus can do?

  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Trojan.Ransom.Stop?


File Info:

crc32: B12524BC
md5: b1cfe57dd34b0ab8379733cf3f368be4
name: 5.exe
sha1: 706f7e56d6843a84315c574c2182eb94734f47d3
sha256: 36213f57ceabe23ef76ec56f006c6fc1a1f03a6c94949b0f14b8e6dec26af98b
sha512: b9b61d91d9f6527b5af1b99aff2764a5a4c26da557e94dbec30bdbab7bcc132d3ceb0bbb6c1359555a099a42e8530c2bddaefa7f789f64957f364a9f5542d6b8
ssdeep: 6144:i3LoSRx8VYXCHtFXwSrPpw7Fqsc63phRgIryPoPQDqjbyBuyIPyR02iL18EmxfO:QEsx8RHwSdw7FP5/gIrEdDq6jnRlvxf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Xabitozecesaji. Pezamuhawumeb dayihariduca. Pobotiyayuta wicavakepiyepe femotofuv
InternalName: binokubino.exe
FileVersion: 28.0.0.45
Translation: 0x0409 0x04e4

Trojan.Ransom.Stop also known as:

MicroWorld-eScanTrojan.GenericKD.32699187
FireEyeGeneric.mg.b1cfe57dd34b0ab8
CAT-QuickHealTrojan.Multi
McAfeeRDN/Generic.grp
MalwarebytesRansom.FileCryptor
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0055b2af1 )
BitDefenderTrojan.GenericKD.32699187
K7GWTrojan ( 0055b2af1 )
Cybereasonmalicious.6d6843
Invinceaheuristic
SymantecPacked.Generic.525
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
GDataTrojan.GenericKD.32699187
KasperskyTrojan.Win32.Chapak.ecgp
AlibabaTrojan:Win32/Chapak.3b0d223b
NANO-AntivirusTrojan.Win32.Chapak.ghmdjt
ViRobotTrojan.Win32.S.Infostealer.474624
RisingTrojan.Wacatac!8.10C01 (TFE:5:QctkJtJDusT)
Endgamemalicious (high confidence)
ComodoMalware@#2r8uymrge3g8b
F-SecureTrojan.TR/Crypt.XPACK.gpqez
DrWebTrojan.Packed2.42094
ZillyaTrojan.Chapak.Win32.84806
TrendMicroTROJ_GEN.R002C0RKA19
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.gc
SophosMal/GandCrab-G
IkarusTrojan.Win32.Krypt
CyrenW32/Trojan.SIOP-2317
JiangminTrojan.Chapak.hsn
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.gpqez
Antiy-AVLTrojan/Win32.Chapak
ArcabitTrojan.Generic.D1F2F333
ZoneAlarmTrojan.Win32.Chapak.ecgp
MicrosoftTrojan:Win32/CryptInject.CB!MTB
AhnLab-V3Trojan/Win32.MalPe.R298432
Acronissuspicious
VBA32BScope.Trojan.Dynamer
ALYacTrojan.Ransom.Stop
MAXmalware (ai score=100)
Ad-AwareTrojan.GenericKD.32699187
CylanceUnsafe
PandaGeneric Malware
ESET-NOD32a variant of Win32/Kryptik.GYDV
TrendMicro-HouseCallTrojan.Win32.SMOKELOAD.SMC2.hp
YandexTrojan.Chapak!
SentinelOneDFI – Suspicious PE
MaxSecureTrojan.Malware.74684616.susgen
FortinetW32/Kryptik.GYEF!tr
BitDefenderThetaGen:NN.ZexaF.32251.Cu0@a8Ev6eg
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.fc8

How to remove Trojan.Ransom.Stop?

Trojan.Ransom.Stop removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

1 Comment

Leave a Comment