Gridinsoft Logo

Lariavts Ransomware STOP/Djvu Analysis

Ransomware STOP/Djvu
Updated on 2024-06-19 (6 months ago)
Checked by Online Virus Scanner
Online Virus Checker v.1.0.179.174
DB Version: 2024-06-19 21:00:29

Ransom.Win32.STOP.dd!se45814

STOP/Djvu Ransomware, also known simply as STOP Ransomware or Djvu Ransomware, is a type of malicious software that encrypts the files on a victim's computer and demands a ransom for their decryption. This ransomware variant has been active for several years and has affected numerous users and organizations.

File Lariavts
Checked 2024-06-19 18:40:20
MD5 f52f4f70eea35c76b61d25998a3fc800
SHA1 9ecf5616851cf0c35cfef9047e5d873ff3106017
SHA256 bc59e033df4fb938c03ffaf274aba1a639efb5163cf84a4fc5beb6026e562dcf
SHA512 8f2f4661cc2fccfe23ee99e8f453cd756800704ee9e0830b1d43ef216e0c1b8e8d9414df86ad10a9a52d7678319ff3b7ccd4cc2efb533f0c730f0c919c0cb086
Imphash 9ddb1fabeee3b3905613cd98d52e8a73
File Size 215552 bytes

Ransom.Win32.STOP.dd!se45814 Removal

Ransom.Win32.STOP.dd!se45814 Removal

Gridinsoft has the capability to identify and eliminate Ransom.Win32.STOP.dd!se45814 without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

File Version Information

OriginalFilename Lariavts
ProductsVersion 21.59.2.52
ProdeuctionVersion 25.50.25.70
Translation 0x28ae 0x0e7e

Portable Executable Info

14d7e34b02f46e4dec36816d716deebc
bdff42d6c84a72fabe5e6a9e7d584b5a
bcf9f6f2e0c4ebf4
Image Base: 0x00400000
Entry Point: 0x0040308f
Compilation: 2022-08-01 21:51:17
Checksum: 0x00037320 (Actual: 0x00037320)
OS Version: 5.0
PDB Path: C:\nicaziwic.pdb
PEiD: PE32 executable (GUI) Intel 80386, for MS Windows
Sign: The PE file does not contain a certificate table.
Sections: 4
Imports: KERNEL32, USER32, GDI32, ADVAPI32,
Exports: 0
Resources: 21

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
.text 0x00001000 0x00024002 0x00024200 2e3d3e39e9bc5be42a26215b55746d12 7.39
.rdata 0x00026000 0x0000322a 0x00003400 06537fe23959d431b74909ad65a4ec6d 5.20
.data 0x0002a000 0x004206f8 0x00001800 0df8a594e674ea3d2654b17e17e2654a 3.22
.rsrc 0x0044b000 0x0000b6e8 0x0000b800 7a5ed2a0913143ed287d87d9c10956ae 4.13

Leave a comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware