Ransom

Generic.Ransom.Buhtrap.00A5040C removal instruction

Malware Removal

The Generic.Ransom.Buhtrap.00A5040C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Buhtrap.00A5040C virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to stop active services
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Clears Windows events or logs
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.Buhtrap.00A5040C?


File Info:

crc32: FC3A8E9C
md5: 664c0c03afa4e2a42f4929bfba8c42db
name: 664C0C03AFA4E2A42F4929BFBA8C42DB.mlw
sha1: c89bed18c6d1ed816e3e620701643031b3bd5069
sha256: f3d4f1c1e35599b44207ecd23d06cd4f9947bcdf075756954dcd9dec83f72d0b
sha512: 88bd08be13b320ad07c04ba11616b3648d94880041864b03b3e2d6d035a5f37ccb83165fe3bce0626a35a994acc1edb0ee26d46d970bdb10c5798fb47bbb3c59
ssdeep: 6144:tia17rttjwiwEdkw3/K6r2/2J4DQFu/U3buRKlemZ9DnGAeTM6Y8STB+8:tXttjwehS6rqM4DQFu/U3buRKlemZ9D
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Buhtrap.00A5040C also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055c8001 )
Elasticmalicious (high confidence)
DrWebDLOADER.Trojan
CynetMalicious (score: 100)
ALYacTrojan.Ransom.VegaLocker
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/dropper.ali1003001
K7GWTrojan ( 0055c8001 )
Cybereasonmalicious.3afa4e
SymantecDownloader
ESET-NOD32a variant of Win32/Filecoder.Buran.J
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderGeneric.Ransom.Buhtrap.00A5040C
NANO-AntivirusTrojan.Win32.Filecoder.ijjwyn
MicroWorld-eScanGeneric.Ransom.Buhtrap.00A5040C
Ad-AwareGeneric.Ransom.Buhtrap.00A5040C
SophosMal/Generic-R + Mal/Behav-010
F-SecureHeuristic.HEUR/Malware
BitDefenderThetaAI:Packer.DBAF84931F
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.ZEPPELIN.SMTH
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.664c0c03afa4e2a4
EmsisoftGeneric.Ransom.Buhtrap.00A5040C (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
AviraHEUR/Malware
Antiy-AVLTrojan[Ransom]/Win32.Buran.a
MicrosoftRansom:Win32/Zeppelin.A!MSR
ArcabitGeneric.Ransom.Buhtrap.00A5040C
AegisLabTrojan.Win32.Agent.4!c
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
GDataGeneric.Ransom.Buhtrap.00A5040C
AhnLab-V3Trojan/Win32.BuhTrap.R338445
McAfeeGenericRXKB-RP!664C0C03AFA4
MAXmalware (ai score=80)
VBA32BScope.Trojan.Agent
MalwarebytesRansom.Zeppelin
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom.Win32.ZEPPELIN.SMTH
RisingRansom.Agent!8.6B7 (CLOUD)
YandexTrojan.GenAsa!CxfKQU+AivY
IkarusTrojan-Ransom.Buran
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Buran.H!tr.ransom
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Zeppelin.HwUBrjsA

How to remove Generic.Ransom.Buhtrap.00A5040C?

Generic.Ransom.Buhtrap.00A5040C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment