Ransom Trojan

Trojan-Ransom.Win32.Stop.fe malicious file

Malware Removal

The Trojan-Ransom.Win32.Stop.fe file is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Trojan-Ransom.Win32.Stop.fe virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Ransom.Win32.Stop.fe?


General:

Operating System: Windows 7 / 8 / 8.1 / 10 Virus Name: GenericR-RGH!C25EF68E3F18

File Info:

Name: starticon8.exe

Size: 1282560

Type: PE32 executable (GUI) Intel 80386, for MS Windows

MD5: c25ef68e3f182a258cc00ccc01c985e2

SHA1: 498e57ef53f9a5deec7a08edfe8dd881e70a68d2

SH256: 1b359f5e2446a66b1e44143fabdfe23de8c237e93eeae0e973646dd205a645a7

Version Info:

[No Data]

Trojan-Ransom.Win32.Stop.fe also known as:

ALYacTrojan.Ransom.Stop
APEXMalicious
AVGWin32:CoinminerX-gen [Trj]
Acronissuspicious
Ad-AwareTrojan.GenericKD.32667992
AegisLabTrojan.Win32.Stop.j!c
AhnLab-V3Trojan/Win32.MalPe.R296857
AlibabaTrojan:Win32/Stop.5e859e19
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Generic.D1F27958
AvastWin32:CoinminerX-gen [Trj]
AviraTR/AD.InstaBot.cou
BitDefenderTrojan.GenericKD.32667992
BitDefenderThetaGen:Trojan.Heur2.PPBB.3.0.oz0@bKMJPpnaVd
BkavW32.WisampleNWAH.Trojan
CAT-QuickHealTrojan.Multi
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.e3f182
CylanceUnsafe
CyrenW32/Trojan.UJRE-7480
DrWebTrojan.PWS.Siggen2.37718
ESET-NOD32a variant of Win32/Kryptik.GXUX
EmsisoftTrojan.Crypt (A)
Endgamemalicious (high confidence)
F-SecureTrojan.TR/AD.InstaBot.cou
FireEyeGeneric.mg.c25ef68e3f182a25
FortinetW32/GenKryptik.DWRG!tr
GDataWin32.Trojan-Ransom.STOP.R7VRLW
IkarusTrojan.Win32.Crypt
Invinceaheuristic
JiangminTrojanDownloader.Bandit.atg
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
KasperskyTrojan-Ransom.Win32.Stop.fe
MAXmalware (ai score=100)
MalwarebytesTrojan.MalPack.GS
McAfeeGenericR-RGH!C25EF68E3F18
McAfee-GW-EditionGenericR-RGH!C25EF68E3F18
MicroWorld-eScanTrojan.GenericKD.32667992
MicrosoftTrojan:Win32/CryptInject.VDS!MTB
NANO-AntivirusTrojan.Win32.Stop.gfpkck
Paloaltogeneric.ml
PandaTrj/GdSda.A
Qihoo-360Win32/Trojan.Ransom.1f9
RisingTrojan.Kryptik!1.BE23 (CLASSIC)
SentinelOneDFI – Malicious PE
SophosMal/GandCrab-G
SymantecDownloader
Trapminemalicious.moderate.ml.score
TrendMicroRansom_Stop.R002C0WK219
TrendMicro-HouseCallTrojan.Win32.SMOKELOAD.SMD2.hp
VBA32BScope.Trojan.Chapak
VIPRETrojan.Win32.Generic!BT
WebrootW32.Trojan.Gen
YandexTrojan.Stop!
ZillyaTrojan.Stop.Win32.31
ZoneAlarmTrojan-Ransom.Win32.Stop.fe

How to remove Trojan-Ransom.Win32.Stop.fe?

Trojan-Ransom.Win32.Stop.fe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment