Ransom

Generic.Ransom.Babuk.A.54E0147A removal tips

Malware Removal

The Generic.Ransom.Babuk.A.54E0147A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Babuk.A.54E0147A virus can do?

  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Appends a known multi-family ransomware file extension to files that have been encrypted
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Ransom.Babuk.A.54E0147A?


File Info:

crc32: 7C178546
md5: 4b4ed15014cad303edf6ceafedb3d594
name: 4B4ED15014CAD303EDF6CEAFEDB3D594.mlw
sha1: bc327c544d5cdce1b7112a6ab389a14a803fa2dc
sha256: 12c561ac827c3f79afff026b0b1d3ddec7c4b591946e2b794a4d00c423b1c8f8
sha512: bc35af57a4798b7b8490ceb2a74fda06c866a4e0854b3a754fd81cfd2bf8319aedc6da5f9d9ec5caac835f2ddd37a508e9fc8a5748344928c4ace19af9ed133d
ssdeep: 1536:H6YdRu8JyExlsrQLOJgY8ZZP8LHD4XWaNH71dLdG1iiFM2iG2icf5:rdRuBClsrQLOJgY8Zp8LHD4XWaNH71d
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Babuk.A.54E0147A also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
ClamAVWin.Ransomware.Maze-7473772-0
ALYacGeneric.Ransom.Babuk.A.54E0147A
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 005782fe1 )
K7AntiVirusTrojan ( 005782fe1 )
SymantecRansom.Babuk
ESET-NOD32a variant of Win32/Filecoder.Babyk.A
APEXMalicious
AvastWin32:Dh-A [Heur]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderGeneric.Ransom.Babuk.A.54E0147A
MicroWorld-eScanGeneric.Ransom.Babuk.A.54E0147A
Ad-AwareGeneric.Ransom.Babuk.A.54E0147A
SophosML/PE-A
F-SecureTrojan.TR/Crypt.EPACK.Gen2
BitDefenderThetaGen:NN.ZexaF.34142.euW@a4byQNd
TrendMicroRansom.Win32.BABUK.SMRD1
McAfee-GW-EditionBehavesLike.Win32.Agent.lm
FireEyeGeneric.mg.4b4ed15014cad303
EmsisoftTrojan.FileCoder (A)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.EPACK.Gen2
MicrosoftRansom:Win32/Babuk.MAK!MTB
ArcabitGeneric.Ransom.Babuk.A.54E0147A
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataGeneric.Ransom.Babuk.A.54E0147A
AhnLab-V3Ransomware/Win.Babuk.R440335
Acronissuspicious
McAfeeGenericRXNS-AS!4B4ED15014CA
MAXmalware (ai score=85)
VBA32BScope.TrojanRansom.Crypmod
MalwarebytesMalware.AI.3103134655
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom.Win32.BABUK.SMRD1
RisingRansom.Babuk!1.D7A0 (CLASSIC)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/FilecoderProt.F183!tr.ransom
AVGWin32:Dh-A [Heur]

How to remove Generic.Ransom.Babuk.A.54E0147A?

Generic.Ransom.Babuk.A.54E0147A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment