Ransom

Generic.Ransom.Buhtrap.94D90180 removal

Malware Removal

The Generic.Ransom.Buhtrap.94D90180 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Buhtrap.94D90180 virus can do?

  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Code injection with CreateRemoteThread in a remote process
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Likely virus infection of existing system binary
  • Clears Windows events or logs
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.Buhtrap.94D90180?


File Info:

crc32: 97372FF6
md5: cffe48eed73a2006503d1094dd7e07bf
name: CFFE48EED73A2006503D1094DD7E07BF.mlw
sha1: 2484ea7e8661d7f21aadb7fb4d79748bc7baae73
sha256: 4f7f151c4baa92b192d53da2d3338b7111653ed4bd8e61f6e0696164068f7144
sha512: 959cd0e7ad00e019301747b0eb4f080f1e2227d360f01f6095c7fc2a8876158b1fbe644f9fc5156c290bbf756a62df26244cc3a94f811cdd9f6ef67c422af5eb
ssdeep: 6144:2C617rttjwFQEdkQXxmW6rWf2J4DQFu/U3buRKlemZ9DnGAezMibyhZ+8:2Xttjw7BhmW6rqM4DQFu/U3buRKlemZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Buhtrap.94D90180 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055c8001 )
Elasticmalicious (high confidence)
DrWebDLOADER.Trojan
CynetMalicious (score: 100)
ALYacTrojan.Ransom.VegaLocker
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/dropper.ali1003001
K7GWTrojan ( 0055c8001 )
Cybereasonmalicious.ed73a2
SymantecDownloader
ESET-NOD32a variant of Win32/Filecoder.Buran.J
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderGeneric.Ransom.Buhtrap.94D90180
MicroWorld-eScanGeneric.Ransom.Buhtrap.94D90180
TencentWin32.Trojan.Raas.Auto
Ad-AwareGeneric.Ransom.Buhtrap.94D90180
SophosMal/Generic-R + Mal/Behav-010
ComodoMalware@#356ty9y7ojn71
BitDefenderThetaAI:Packer.EE5BC08E1F
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.ZEPPELIN.SMTH
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.cffe48eed73a2006
EmsisoftGeneric.Ransom.Buhtrap.94D90180 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.AGent.Gen
AviraHEUR/Malware
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Zeppelin.A!MSR
ArcabitGeneric.Ransom.Buhtrap.94D90180
AegisLabTrojan.Win32.Agent.4!c
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
GDataGeneric.Ransom.Buhtrap.94D90180
AhnLab-V3Trojan/Win32.BuhTrap.R338445
McAfeeGenericRXKB-RP!CFFE48EED73A
MAXmalware (ai score=88)
VBA32BScope.Trojan.Agent
MalwarebytesRansom.Zeppelin
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom.Win32.ZEPPELIN.SMTH
RisingTrojan.Filecoder!8.68 (CLOUD)
IkarusTrojan-Ransom.Buran
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Buran.H!tr.ransom
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Zeppelin.HwUBn6YA

How to remove Generic.Ransom.Buhtrap.94D90180?

Generic.Ransom.Buhtrap.94D90180 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment