Ransom Trojan

Trojan-Ransom.Win32.Stop.fh removal guide

Malware Removal

The Trojan-Ransom.Win32.Stop.fh file is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Trojan-Ransom.Win32.Stop.fh virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Ransom.Win32.Stop.fh?


General:

Operating System: Windows 7 / 8 / 8.1 / 10 Virus Name: Trojan-Ransom.Win32.Stop.fh

File Info:

Name: starticon11.exe

Size: 763904

Type: PE32 executable (GUI) Intel 80386, for MS Windows

MD5: 23c27e8bdb1ff3db612870d99286da5d

SHA1: 55f645e84e402af7faaf50e92032f3283ea7e7c6

SH256: 4598a0c09cb160c295b10c02d3ccfb261cd728b11f4fd1d47db21702100670bd

Version Info:

[No Data]

Trojan-Ransom.Win32.Stop.fh also known as:

ALYacTrojan.Ransom.Stop
APEXMalicious
AVGWin32:TrojanX-gen [Trj]
Acronissuspicious
Ad-AwareTrojan.GenericKD.32674719
AegisLabTrojan.Win32.Zbot.m6l9
AhnLab-V3Malware/Win32.RL_Generic.R297159
AlibabaTrojan:Win32/Stop.a7f65fe9
Antiy-AVLTrojan[Ransom]/Win32.Stop
ArcabitTrojan.Generic.D1F2939F
AvastWin32:TrojanX-gen [Trj]
AviraTR/AD.InstaBot.csq
BitDefenderTrojan.GenericKD.32674719
BitDefenderThetaGen:NN.ZexaF.32248.UGW@aSMI64c
CAT-QuickHealTrojan.Multi
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.84e402
CylanceUnsafe
CyrenW32/Trojan.VQFX-3013
DrWebTrojan.Siggen8.53111
ESET-NOD32a variant of Win32/Kryptik.GXWX
Endgamemalicious (high confidence)
F-ProtW32/Kryptik.API.gen!Eldorado
F-SecureTrojan.TR/AD.InstaBot.csq
FireEyeGeneric.mg.23c27e8bdb1ff3db
FortinetW32/GenKryptik.DWUH!tr
GDataTrojan.GenericKD.32674719
IkarusTrojan.Win32.Krypt
Invinceaheuristic
JiangminTrojan.Selfdel.pka
K7AntiVirusTrojan ( 0055ad751 )
K7GWTrojan ( 0055ad751 )
KasperskyTrojan-Ransom.Win32.Stop.fh
MAXmalware (ai score=100)
MalwarebytesTrojan.MalPack.GS.Generic
MaxSecureTrojan.Malware.300983.susgen
McAfeeRDN/Generic.dx
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.bc
MicroWorld-eScanTrojan.GenericKD.32674719
MicrosoftTrojan:Win32/Predator.PA!MTB
NANO-AntivirusTrojan.Win32.GenKryptik.gfoscf
Paloaltogeneric.ml
PandaTrj/GdSda.A
Qihoo-360Win32/Trojan.Ransom.387
RisingTrojan.Kryptik!1.BED3 (CLASSIC)
SentinelOneDFI – Malicious PE
SophosMal/GandCrab-G
SymantecPacked.Generic.525
Trapminemalicious.moderate.ml.score
TrendMicroRansom_Stop.R002C0PK419
TrendMicro-HouseCallRansom_Stop.R002C0PK419
VBA32BScope.TrojanPSW.Azorult
VIPRETrojan.Win32.Generic!BT
ViRobotTrojan.Win32.StopRansom.763904.A
WebrootW32.Trojan.Gen
YandexTrojan.Stop!
ZillyaTrojan.Stop.Win32.32
ZoneAlarmTrojan-Ransom.Win32.Stop.fh
eGambitUnsafe.AI_Score_98%

How to remove Trojan-Ransom.Win32.Stop.fh?

Trojan-Ransom.Win32.Stop.fh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment