Ransom Trojan

What is “Trojan-Ransom.Win32.Stop”?

Malware Removal

The Trojan-Ransom.Win32.Stop is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Stop virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Tatar
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

api.2ip.ua
plnv.top

How to determine Trojan-Ransom.Win32.Stop?


File Info:

crc32: 2E5DEDC3
md5: 32f3be8697cbd7c40c05ee83318ae14c
name: 32F3BE8697CBD7C40C05EE83318AE14C.mlw
sha1: 9e58be40a590755bfb204d2d2f40d2de26bf4542
sha256: 6c747049b34b13fee03f951bc3b0f330aab130d3f1ecd4e39df734a94d4442d1
sha512: 9b2a9afdc989e77e0a6cdd283b41958b2bb2162c1ff4a711c5f54c935d0c7628516f85ff64fe5d6e5dfed5175ceb4e3b0a01d18ee606a1d2ff293b09da0ecabb
ssdeep: 12288:6zVWziqF+qpKMHLWbPeJsyixMNOELgd2fsKpcHuRy1GmBzsEWJOifJNUyCt:6ZLqF+qLHAGPVOSpcu9EoLyy
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: calinilimodumator.exe
FileVersions: 7.0.0.23
LegalCopyrights: Vsekdag
ProductVersions: 67.0.20.45
Translation: 0x0409 0x22fc

Trojan-Ransom.Win32.Stop also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.73131
FireEyeGeneric.mg.32f3be8697cbd7c4
CAT-QuickHealTrojanransom.Stop
ALYacTrojan.Ransom.Stop
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKDZ.73131
K7GWTrojan ( 005783f91 )
K7AntiVirusTrojan ( 005783f91 )
CyrenW32/Azorult.P.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BotX-gen [Trj]
ClamAVWin.Dropper.Mokes-9835362-0
KasperskyHEUR:Trojan-Ransom.Win32.Stop.gen
AlibabaRansom:Win32/generic.ali2000027
NANO-AntivirusTrojan.Win32.Stop.imjfpm
TencentWin32.Trojan.Raas.Auto
Ad-AwareTrojan.GenericKDZ.73131
EmsisoftTrojan.Crypt (A)
F-SecureTrojan.TR/AD.InstaBot.BH
DrWebTrojan.Hosts.48251
TrendMicroTrojanSpy.Win32.RANSOM.USMANBP21
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SophosMal/Generic-S
IkarusTrojan.WinGo.Ranumbot
WebrootW32.Trojan.Gen
AviraTR/AD.InstaBot.BH
MicrosoftTrojan:Win32/Azorult.MZ!MTB
GridinsoftTrojan.Win32.Kryptik.vb
ArcabitTrojan.Generic.D11DAB
ZoneAlarmHEUR:Trojan-Ransom.Win32.Stop.gen
GDataTrojan.GenericKDZ.73131
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R367821
Acronissuspicious
McAfeeRDN/Ransom
MAXmalware (ai score=87)
VBA32BScope.Backdoor.Mokes
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HJPL
TrendMicro-HouseCallTrojanSpy.Win32.RANSOM.USMANBP21
RisingRansom.Stop!8.10810 (CLOUD)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_88%
FortinetW32/GenKryptik.FCCE!tr
BitDefenderThetaGen:NN.ZexaF.34590.YG0@aqqPEFhG
AVGWin32:BotX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwoCdygA

How to remove Trojan-Ransom.Win32.Stop?

Trojan-Ransom.Win32.Stop removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment