Ransom

What is “Generic.Ransom.Buhtrap.6420B2E1”?

Malware Removal

The Generic.Ransom.Buhtrap.6420B2E1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Buhtrap.6420B2E1 virus can do?

  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Code injection with CreateRemoteThread in a remote process
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Likely virus infection of existing system binary
  • Clears Windows events or logs
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.Buhtrap.6420B2E1?


File Info:

crc32: 0C80407A
md5: 6607d8c1a28d7538e2a6565cf40d1260
name: 6607D8C1A28D7538E2A6565CF40D1260.mlw
sha1: f618879c011cde344066072949f025827feea663
sha256: 594df9c402abfdc3c838d871c3395ac047f256b2ac2fd6ff66b371252978348d
sha512: a8ad82f25778b771861a9d0c2346b62883e82d401b4ca6ffd9fd035e34bc6a8728be49c01cb87cd7456200354193a070e9b874cf6e270c903cab184332ad05af
ssdeep: 6144:ryJE1yd7WWlJmcyfwAPWna4DQFu/U3buRKlemZ9DnGAevIGG8v+:rU/d7WWKvhPWa4DQFu/U3buRKlemZ9D
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Buhtrap.6420B2E1 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055c8001 )
Elasticmalicious (high confidence)
DrWebDLOADER.Trojan
CynetMalicious (score: 100)
CAT-QuickHealTrojan.AgentIH.S18008568
ALYacGeneric.Ransom.Buhtrap.6420B2E1
CylanceUnsafe
SangforWorm.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 0055c8001 )
Cybereasonmalicious.1a28d7
CyrenW32/Ransom.LV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Buran.J
APEXMalicious
AvastWin32:Dh-A [Heur]
ClamAVWin.Ransomware.Buhtrap-9865977-0
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderGeneric.Ransom.Buhtrap.6420B2E1
MicroWorld-eScanGeneric.Ransom.Buhtrap.6420B2E1
Ad-AwareGeneric.Ransom.Buhtrap.6420B2E1
SophosML/PE-A + Mal/Behav-010
BitDefenderThetaAI:Packer.F3A59F911F
TrendMicroRansom.Win32.ZEPPELIN.SMTH
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.6607d8c1a28d7538
EmsisoftGeneric.Ransom.Buhtrap.6420B2E1 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/Malware
Antiy-AVLTrojan/Generic.ASCommon.195
MicrosoftRansom:Win32/Zeppelin.A!MSR
ArcabitGeneric.Ransom.Buhtrap.6420B2E1
GDataGeneric.Ransom.Buhtrap.6420B2E1
AhnLab-V3Trojan/Win32.BuhTrap.R338445
McAfeeGenericRXKB-RP!6607D8C1A28D
MAXmalware (ai score=88)
VBA32BScope.Trojan.Agent
MalwarebytesRansom.Zeppelin
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.ZEPPELIN.SMTH
RisingRansom.Zeppelin!1.D4C1 (CLASSIC)
IkarusTrojan-Ransom.Buran
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Buran.H!tr.ransom
AVGWin32:Dh-A [Heur]

How to remove Generic.Ransom.Buhtrap.6420B2E1?

Generic.Ransom.Buhtrap.6420B2E1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment