Ransom

Generic.Ransom.Babuk.A.117B2818 removal tips

Malware Removal

The Generic.Ransom.Babuk.A.117B2818 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Babuk.A.117B2818 virus can do?

  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.Babuk.A.117B2818?


File Info:

crc32: 0DF4B523
md5: 1ef35891eec353a7ca44a4287f8bf3fd
name: 1EF35891EEC353A7CA44A4287F8BF3FD.mlw
sha1: a9e4fb4258f409b1896434e6b8b2e7290120cebe
sha256: 9caa8e8a98ef7841c1b230c22f78b5c10aa9348a2bfd0dfe2670853b6d0ba92c
sha512: 235ed7ab2178b5a80b2d7e0bdf8bc70acdb5cca6ba31f889bd3ecb14a523dbfaf01a97042eff465ac8955e40bb385fd31c8acdac4e626d8d67e560bc31821cef
ssdeep: 1536:EW6DhZM4hubesrQLOJgY8ZZP8LHD4XWaNH71dLdG1iiFM2iG2zs4:UhZ5YesrQLOJgY8Zp8LHD4XWaNH71dL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Babuk.A.117B2818 also known as:

K7AntiVirusTrojan ( 005782fe1 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen12.62665
ClamAVWin.Ransomware.Maze-7473772-0
McAfeeGenericRXAA-AA!1EF35891EEC3
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 005782fe1 )
Cybereasonmalicious.1eec35
CyrenW32/Babyk.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Babyk.A
APEXMalicious
AvastWin32:Dh-A [Heur]
CynetMalicious (score: 100)
KasperskyVHO:Trojan-Ransom.Win32.Agent.gen
BitDefenderGeneric.Ransom.Babuk.A.117B2818
NANO-AntivirusTrojan.Win32.Ransom.iuaipi
ViRobotTrojan.Win32.Ransom.80896.E
MicroWorld-eScanGeneric.Ransom.Babuk.A.117B2818
Ad-AwareGeneric.Ransom.Babuk.A.117B2818
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34790.euW@aWBl0ug
TrendMicroRansom.Win32.BABUK.SMRD1
FireEyeGeneric.mg.1ef35891eec353a7
EmsisoftGeneric.Ransom.Babuk.A.117B2818 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.EPACK.Gen2
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitGeneric.Ransom.Babuk.A.117B2818
GDataGeneric.Ransom.Babuk.A.117B2818
AhnLab-V3Trojan/Win32.BabukRansom.C4337300
Acronissuspicious
VBA32BScope.TrojanRansom.Gen
MAXmalware (ai score=88)
MalwarebytesRansom.Babuk
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.BABUK.SMRD1
RisingRansom.Babuk!1.D7A0 (CLASSIC)
IkarusTrojan-Ransom.Babyk
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/FilecoderProt.F183!tr.ransom
AVGWin32:Dh-A [Heur]
Qihoo-360HEUR/QVM20.1.897B.Malware.Gen

How to remove Generic.Ransom.Babuk.A.117B2818?

Generic.Ransom.Babuk.A.117B2818 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment