Ransom

Generic.Ransom.Babuk.A.7C60B4F1 removal

Malware Removal

The Generic.Ransom.Babuk.A.7C60B4F1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Babuk.A.7C60B4F1 virus can do?

  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Manipulates data from or to the Recycle Bin
  • The binary contains an unknown PE section name indicative of packing
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • CAPE detected the Babuk malware family
  • Creates a known Babuk ransomware decryption instruction / key file.

How to determine Generic.Ransom.Babuk.A.7C60B4F1?


File Info:

name: F47D2AFDCD64B02CDA5F.mlw
path: /opt/CAPEv2/storage/binaries/9a2952148f342468fb1f7acee9ce1de2eae6eb6b63657d40169dc0196b6cd2c6
crc32: C293DAE0
md5: f47d2afdcd64b02cda5f5305564bb8f5
sha1: 03f44e695cfa3d7dc87a48f971e3778c71fc0c6b
sha256: 9a2952148f342468fb1f7acee9ce1de2eae6eb6b63657d40169dc0196b6cd2c6
sha512: accc108fcef9e39876df7887a36720c5a4024fc17ad13e7095de5e6758aef070196de15fd894565d04d5f21ab15d1393aed7c3b0bdda454bf445359e670ff602
ssdeep: 6144:cTSScdnTVJ5/iw7rWDxf0Hqf1TPd731uVERN/sHjuWvn6:CQJ5aw7rWDxf0Hqf1bdFwjuWv6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14BC43B507984C261DDE320B4C6ECB171813D68F0176199CBA6841BFAEBE42D4AB37F5B
sha3_384: 607b0ce9237e12cbbec08dcc739a1d2ce4441c6ee5726973b34803bd3c19ea41a7c2d2cc2540f5b7abef55a7d6004c2e
ep_bytes: e964c80200e908e80600e993750500e9
timestamp: 2021-12-08 00:36:42

Version Info:

0: [No Data]

Generic.Ransom.Babuk.A.7C60B4F1 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Babuk.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeeArtemis!F47D2AFDCD64
CylanceUnsafe
K7AntiVirusTrojan ( 005786171 )
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 005786171 )
Cybereasonmalicious.95cfa3
ESET-NOD32a variant of Win32/Filecoder.Babyk.A
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Ransomware.Babuk-9819006-0
KasperskyTrojan-Ransom.Win32.Encoder.ooh
BitDefenderDeepScan:Generic.Ransom.Babuk.A.7C60B4F1
MicroWorld-eScanDeepScan:Generic.Ransom.Babuk.A.7C60B4F1
AvastWin32:MalwareX-gen [Trj]
TencentMalware.Win32.Gencirc.11db3f55
Ad-AwareDeepScan:Generic.Ransom.Babuk.A.7C60B4F1
SophosGeneric ML PUA (PUA)
DrWebTrojan.Encoder.34687
TrendMicroRansom_Encoder.R002C0WLB21
FireEyeGeneric.mg.f47d2afdcd64b02c
EmsisoftDeepScan:Generic.Ransom.Babuk.A.7C60B4F1 (B)
IkarusTrojan-Ransom.Babyk
GDataDeepScan:Generic.Ransom.Babuk.A.7C60B4F1
JiangminTrojan.Encoder.anw
AviraTR/Encoder.pgzbl
Antiy-AVLTrojan/Generic.ASCommon.207
GridinsoftRansom.Win32.Gen.sa
ArcabitDeepScan:Generic.Ransom.Babuk.A.7C60B4F1
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.Generic.C4823973
VBA32BScope.TrojanRansom.Crypmod
ALYacDeepScan:Generic.Ransom.Babuk.A.7C60B4F1
MAXmalware (ai score=82)
MalwarebytesRansom.FileCryptor
TrendMicro-HouseCallRansom_Encoder.R002C0WLB21
SentinelOneStatic AI – Suspicious PE
FortinetW32/Filecoder_Babyk.A!tr.ransom
AVGWin32:MalwareX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Generic.Ransom.Babuk.A.7C60B4F1?

Generic.Ransom.Babuk.A.7C60B4F1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment