Ransom

Should I remove “Generic.Ransom.Buhtrap.ABE87FC9”?

Malware Removal

The Generic.Ransom.Buhtrap.ABE87FC9 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Buhtrap.ABE87FC9 virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Likely virus infection of existing system binary
  • Clears Windows events or logs
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.Buhtrap.ABE87FC9?


File Info:

crc32: C350CEE9
md5: 8a22137ddd1fbff611235ef80f2889a9
name: 8A22137DDD1FBFF611235EF80F2889A9.mlw
sha1: 32353e856b0dd5c1ec40288fc04bf6a70b445fe0
sha256: be42aa09fe8112622ba90f7586e52509594019db376c0f1c4897f3e98fa30db4
sha512: e42ec7000ad8f4e2775f07da985583d9c0e8c92225f5b73c02a55a407c899bbb405078e5c095f26d9964a905971ad39da4b9b2b60396b871f88868b6213428b6
ssdeep: 6144:ByJE1brNNDwMAE9kgHQY6LGv2J4DQFu/U3buRKlemZ9DnGAeDMS35mu+c:BUqNNDwYRd6LqM4DQFu/U3buRKlemZ9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Buhtrap.ABE87FC9 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055c8001 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.33275
CynetMalicious (score: 100)
CAT-QuickHealTrojan.AgentIH.S18008568
ALYacGeneric.Ransom.Buhtrap.ABE87FC9
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.17326
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderGeneric.Ransom.Buhtrap.ABE87FC9
K7GWTrojan ( 0055c8001 )
Cybereasonmalicious.ddd1fb
CyrenW32/Ransom.LV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Buran.J
APEXMalicious
KasperskyHEUR:Trojan.Win32.Agent.gen
MicroWorld-eScanGeneric.Ransom.Buhtrap.ABE87FC9
Ad-AwareGeneric.Ransom.Buhtrap.ABE87FC9
SophosML/PE-A + Mal/Behav-010
BitDefenderThetaAI:Packer.9F792C901F
TrendMicroRansom.Win32.ZEPPELIN.SMTH
McAfee-GW-EditionBehavesLike.Win32.ExploitMydoom.dh
FireEyeGeneric.mg.8a22137ddd1fbff6
EmsisoftGeneric.Ransom.Buhtrap.ABE87FC9 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/Malware
Antiy-AVLTrojan/Generic.ASCommon.195
KingsoftWin32.Heur.KVMH017.a.(kcloud)
MicrosoftRansom:Win32/Zeppelin.A!MSR
ArcabitGeneric.Ransom.Buhtrap.ABE87FC9
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
GDataGeneric.Ransom.Buhtrap.ABE87FC9
AhnLab-V3Trojan/Win32.BuhTrap.R338445
McAfeeGenericRXKB-RP!8A22137DDD1F
MAXmalware (ai score=88)
VBA32BScope.Trojan.Agent
MalwarebytesRansom.Zeppelin
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.ZEPPELIN.SMTH
RisingRansom.Zeppelin!1.D4C1 (CLASSIC)
YandexTrojan.GenAsa!CxfKQU+AivY
IkarusTrojan-Ransom.Buran
FortinetW32/Buran.H!tr.ransom
Qihoo-360Win32/Ransom.Zeppelin.HwUBEIkA

How to remove Generic.Ransom.Buhtrap.ABE87FC9?

Generic.Ransom.Buhtrap.ABE87FC9 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment