Threat Database Ransomware Stop.PCQQ.RRBB Ransomware

Stop.PCQQ.RRBB Ransomware

By CagedTech in Ransomware

Threat Scorecard

Popularity Rank: 5,939
Threat Level: 100 % (High)
Infected Computers: 31,932
First Seen: May 13, 2021
Last Seen: July 17, 2026
OS(es) Affected: Windows

The detection of Stop.PCQQ.RRBB Ransomware indicates that your system has been compromised by a type of malware that can cause significant damage to your files and data. Ransomware is a serious threat that can encrypt your files, making them inaccessible until a ransom is paid. However, paying the ransom does not guarantee that your files will be restored, and it is essential to take immediate action to remove the malware and prevent further damage.

What Is Stop.PCQQ.RRBB Ransomware?

Ransomware is a type of malware that uses encryption to hold a victim's files for ransom. It can spread through various means, including phishing emails, infected software downloads, and exploited vulnerabilities. The Stop.PCQQ.RRBB Ransomware detection suggests that your system has been infected with a ransomware variant that can cause significant harm to your data and system stability.

How Stop.PCQQ.RRBB Ransomware Operates

Ransomware typically operates by scanning the system for files to encrypt, using algorithms to lock the files, and then demanding a ransom in exchange for the decryption key. The malware may also attempt to spread to other systems on the network, causing further damage. In some cases, ransomware may also steal sensitive information, such as login credentials or financial data, before encrypting the files.

Symptoms of Infection

Common symptoms of a ransomware infection include files becoming inaccessible, encrypted files with unusual extensions, and ransom demands displayed on the screen. You may also notice that your system is running slowly, or that certain programs are not functioning properly. In some cases, you may receive alerts from your security software indicating that a threat has been detected.

  • Files become inaccessible or are encrypted with unusual extensions
  • Ransom demands displayed on the screen
  • System running slowly or programs not functioning properly
  • Alerts from security software indicating a threat has been detected

How to Remove Stop.PCQQ.RRBB Ransomware

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and remove any detected threats
  3. Uninstall any suspicious programs or software that may be related to the infection
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons
  5. Reboot your system and perform another scan with your anti-malware tool to ensure that the malware has been completely removed

Conclusion

Removing Stop.PCQQ.RRBB Ransomware requires immediate attention to prevent further damage to your system and data. By following the steps outlined above, you can help to ensure that the malware is completely removed and your system is restored to a safe and stable state. It is also essential to take preventative measures to avoid future infections, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when opening emails or downloading attachments from unknown sources.

Analysis Report

General information

Family Name: Stop.PCQQ/RRBB Ransomware
Signature status: No Signature

Known Samples

MD5: 0ca3e9912dabf7d45d28b0365d76788a
SHA1: 2d8e14b0fb0ed6359424aeb9c84dd616552ba3f5
SHA256: 4C3F9871F101CEAB19274E044E17481B85487DE9D0905AF6D69D342B6FB78F6B
File Size: 7.15 MB, 7153152 bytes
MD5: 631e10f06228cf52dfe09f3466f5e648
SHA1: 691c7643da2b41aa94ccb7357de05318a7532319
SHA256: BBBD03831E75FDA593F3C3B883BC39B192FD31811E717312623F46A7B1E75B47
File Size: 1.36 MB, 1363968 bytes
MD5: 24cdd7aec852f3860ce180715395b20e
SHA1: 7627f650ce226bda0cf6f186756b35901621acb0
SHA256: 004D36A7E7A4D9EC2D331277886483CF32508243BF4EB8ED80B939F4CFC26C46
File Size: 419.84 KB, 419840 bytes
MD5: 9935cc29d20e14dc8f59b7315ec6b3fd
SHA1: b3f15a61e553df28a4c4ebcc5a87032d9db82ce0
SHA256: 946B36BE1C841E16A6CB01976180698B668E3BBC8E6DF40F8EFFEFF0BE047486
File Size: 1.36 MB, 1358336 bytes
MD5: 3bbe0da218f5af524b9c4cf4b2c65a7c
SHA1: 53ca0c34d65449090b50f2ae0854bf1bc7817c92
SHA256: 2DFCA6EE1CAAF0B3118E3C747894891E2ACD6807448C8EEA32A854E919F26410
File Size: 393.22 KB, 393216 bytes
Show More
MD5: c16375b20bba2c5d37a79b9431a35df1
SHA1: 3ef56b03c00e6ffd88190f5c05a85410cefab1d9
SHA256: 7BB9F2A8D304F45CD51F3FFA3EE9FB31CADAC026D6EF3A82B0B7179F1BE37F2F
File Size: 446.98 KB, 446976 bytes
MD5: cf53bb58d0129fc48ff4e329f89051e7
SHA1: b6b48370c65d3affcb44430213971f1029b9040d
SHA256: F7AE2C5874B6C574C3BC6BF08FE2B23B91FBBE464A842F8D10CD0C410A54F8EC
File Size: 1.31 MB, 1306112 bytes
MD5: 6cc02dabefffbea1bdc0448df2957cba
SHA1: ba43620aafd9d48451ad5496357b85bb4baf2c29
SHA256: 08F8353255A1F4C4CE1E123C5D1698D5816394798A30B4EFC324BD81BF391779
File Size: 1.46 MB, 1455616 bytes
MD5: 8c5385134a68593d35ce0889cee59701
SHA1: 168453e8757f32a3a6bb26638d7567bb86dcf49e
SHA256: 04506EE20EC6639F11BCF44762117F272B56DF2AC516A4B733120F424AA46FF3
File Size: 558.59 KB, 558592 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Description
  • hgr
  • pgjsq
File Version
  • 5, 0, 0, 0
  • 4, 9, 0, 0
Legal Copyright Copyright (C) 2022
Original Filename
  • hgr.exe
  • pgjsq.exe
Product Version
  • 5, 0, 0, 0
  • 4, 9, 0, 0

File Traits

  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 2,021
Potentially Malicious Blocks: 7
Whitelisted Blocks: 1,994
Unknown Blocks: 20

Visual Map

? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Cridex.C
  • CryptoWall.S
  • Downloader.Agent.XC
  • Gamehack.FHA
  • Gamehack.HIE
Show More
  • Gamehack.NCC
  • Injector.MFA
  • Injector.XG
  • Keygen.FAE
  • Kryptik.BEFH
  • Kryptik.VCHO
  • Kryptik.VCKP
  • Qbot.CDF

Files Modified

File Attributes
c:\users\user\downloads\compile.txt Generic Write,Read Attributes
c:\users\user\downloads\error.txt Generic Write,Read Attributes

Windows API Usage

Category API
Network Winsock2
  • WSAStartup
Network Winsock
  • closesocket
  • connect
  • socket
Encryption Used
  • BCryptOpenAlgorithmProvider

Trending

Most Viewed

Loading...