Categories: Ransom

Should I remove “Generic.Ransom.Basta.A.88A395AA”?

The Generic.Ransom.Basta.A.88A395AA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Basta.A.88A395AA virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to delete or modify volume shadow copies
  • Attempts to modify desktop wallpaper
  • Attempts to restart the guest VM
  • Attempts to stop active services
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Created a service that was not started
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.Basta.A.88A395AA?


File Info:

name: 3F400F30415941348AF2.mlwpath: /opt/CAPEv2/storage/binaries/5d2204f3a20e163120f52a2e3595db19890050b2faa96c6cba6b094b0a52b0aacrc32: C145C63Dmd5: 3f400f30415941348af21d515a2fc6a3sha1: bd0bf9c987288ca434221d7d81c54a47e913600asha256: 5d2204f3a20e163120f52a2e3595db19890050b2faa96c6cba6b094b0a52b0aasha512: 0d4c3ee8807bbbf635ce2d1ce1b747c23cc2724ff999580169e5514c7c97109083bea169bd6a5f8be35f3b679bb8446839fcc7a38f78503658eda306bec69154ssdeep: 12288:TFx0B/O7JxPzW9JPlHKtxYRkG7zLfpXE6SbJ:Rx7zW9JPlGskG1vtype: PE32 executable (console) Intel 80386, for MS Windowstlsh: T182C48D223491C43AE6B203F04DA8DB96617DFC310F6255CBE3C45A6D1A7C5F26B319BAsha3_384: dfb58a778b87a938cdd0a934eb5197735cb2bad672c71798fe871369794ba377378caf74bfcd9fdf3c4fbded6df46f34ep_bytes: e834080000e974feffff8b4df464890dtimestamp: 2022-04-22 20:31:36

Version Info:

0: [No Data]

Generic.Ransom.Basta.A.88A395AA also known as:

Lionic Trojan.Win32.Generic.j!c
tehtris Generic.Malware
MicroWorld-eScan DeepScan:Generic.Ransom.Basta.A.88A395AA
FireEye DeepScan:Generic.Ransom.Basta.A.88A395AA
CAT-QuickHeal Ransom.BlackBasta.S27972135
McAfee RDN/Generic.dx
Cylance Unsafe
Zillya Trojan.Filecoder.Win32.23696
Sangfor Ransom.Win32.Filecoder.V9t5
K7AntiVirus Trojan ( 005921551 )
BitDefender DeepScan:Generic.Ransom.Basta.A.88A395AA
K7GW Trojan ( 005921551 )
CrowdStrike win/malicious_confidence_100% (W)
Arcabit DeepScan:Generic.Ransom.Basta.A.88A395AA
Cyren W32/Trojan.RRHI-8583
Symantec Downloader
Elastic malicious (high confidence)
ESET-NOD32 Win32/Filecoder.BlackBasta.B
APEX Malicious
Paloalto generic.ml
ClamAV Win.Ransomware.BlackBasta-9950287-0
Kaspersky HEUR:Trojan-Ransom.Win32.Generic
Alibaba Ransom:Win32/BlackBasta.6f7786c1
Rising Trojan.Generic@AI.89 (RDML:52yUAxUBxJW3nHPp0RaJmA)
Ad-Aware DeepScan:Generic.Ransom.Basta.A.88A395AA
Emsisoft DeepScan:Generic.Ransom.Basta.A.88A395AA (B)
Comodo Malware@#1eh0bqnll54x9
DrWeb Trojan.Encoder.35576
VIPRE DeepScan:Generic.Ransom.Basta.A.88A395AA
TrendMicro Ransom.Win32.BLACKBASTA.THDBGBB
McAfee-GW-Edition BehavesLike.Win32.Ransomware.hh
Trapmine suspicious.low.ml.score
Ikarus Trojan-Ransom.BlackBasta
Jiangmin Trojan.BlackBasta.a
Webroot W32.Ransom.Stop
Avira TR/FileCoder.ahqwv
Antiy-AVL Trojan/Generic.ASMalwS.6769
Kingsoft Win32.Troj.Undef.(kcloud)
Microsoft Ransom:Win32/Basta.C
GData DeepScan:Generic.Ransom.Basta.A.88A395AA
Cynet Malicious (score: 100)
AhnLab-V3 Ransomware/Win.BastaCrypt.C5103130
BitDefenderTheta Gen:NN.ZexaF.34582.JuW@ay!PGCai
ALYac Trojan.Ransom.Filecoder
MAX malware (ai score=100)
VBA32 BScope.Trojan.DelShad
Malwarebytes Ransom.FileCryptor
Panda Trj/RansomGen.A
TrendMicro-HouseCall Ransom.Win32.BLACKBASTA.THDBGBB
Tencent Win32.Trojan.Filecoder.Lmay
Fortinet W32/Filecoder.OKW!tr.ransom
AVG Win32:Malware-gen
Cybereason malicious.041594
Avast Win32:Malware-gen

How to remove Generic.Ransom.Basta.A.88A395AA?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Trojan.Win32.Agent.xblxqs removal instruction

The Trojan.Win32.Agent.xblxqs is considered dangerous by lots of security experts. When this infection is active,…

2 mins ago

TrojanDownloader:Win32/Wintrim.BH malicious file

The TrojanDownloader:Win32/Wintrim.BH is considered dangerous by lots of security experts. When this infection is active,…

6 mins ago

About “Trojan:Win32/C2Lop.E” infection

The Trojan:Win32/C2Lop.E is considered dangerous by lots of security experts. When this infection is active,…

7 mins ago

Trojan.Dropper.AAAM malicious file

The Trojan.Dropper.AAAM is considered dangerous by lots of security experts. When this infection is active,…

31 mins ago

Win64/Kryptik.EHF removal instruction

The Win64/Kryptik.EHF is considered dangerous by lots of security experts. When this infection is active,…

52 mins ago

Application.Generic.3684796 removal

The Application.Generic.3684796 is considered dangerous by lots of security experts. When this infection is active,…

52 mins ago