Ransom

Generic.Ransom.Buhtrap.CEBC38DB malicious file

Malware Removal

The Generic.Ransom.Buhtrap.CEBC38DB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Buhtrap.CEBC38DB virus can do?

  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Code injection with CreateRemoteThread in a remote process
  • Attempts to delete volume shadow copies
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Clears Windows events or logs
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.Buhtrap.CEBC38DB?


File Info:

crc32: 7868F6C9
md5: 48b844494a746ca96c7b96d6bd90f45f
name: 48B844494A746CA96C7B96D6BD90F45F.mlw
sha1: 7bf83b98f798f3a8f4ce85b6d29554a435e516e3
sha256: 45fba1ef399f41227ae4d14228253237b5eb464f56cab92c91a6a964dc790622
sha512: 4fc6faac283dbd7c7d8b5005804726af50c49e70fa0425562c294dbdd150284ef140dff05e93f745a88088d01d9506280c953a0f39b88029f4379221f875ca86
ssdeep: 6144:4ia1gMHOPDWIhID8X/4DQFu/U3buRKlemZ9DnGAetTsB+G+:4IMH06cID84DQFu/U3buRKlemZ9DnGA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Buhtrap.CEBC38DB also known as:

K7AntiVirusTrojan ( 0055c8001 )
Elasticmalicious (high confidence)
DrWebDLOADER.Trojan
CynetMalicious (score: 100)
CAT-QuickHealTrojan.AgentIH.S18008568
ALYacGeneric.Ransom.Buhtrap.CEBC38DB
CylanceUnsafe
SangforWorm.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0055c8001 )
Cybereasonmalicious.94a746
CyrenW32/Ransom.LV.gen!Eldorado
SymantecRansom.Buran
ESET-NOD32a variant of Win32/Filecoder.Buran.J
APEXMalicious
AvastFileRepMalware
ClamAVWin.Ransomware.Buhtrap-7670115-0
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderGeneric.Ransom.Buhtrap.CEBC38DB
NANO-AntivirusTrojan.Win32.Encoder.hntjph
MicroWorld-eScanGeneric.Ransom.Buhtrap.CEBC38DB
TencentMalware.Win32.Gencirc.11cc11a1
Ad-AwareGeneric.Ransom.Buhtrap.CEBC38DB
SophosML/PE-A + Mal/Behav-010
BitDefenderThetaAI:Packer.6C3AF8981F
TrendMicroRansom.Win32.ZEPPELIN.SMTH
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.48b844494a746ca9
EmsisoftGeneric.Ransom.Buhtrap.CEBC38DB (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/Malware
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASCommon.195
MicrosoftRansom:Win32/Zeppelin.A!MSR
ArcabitGeneric.Ransom.Buhtrap.CEBC38DB
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
GDataWin32.Trojan-Ransom.Filecoder.A79L7W@gen
AhnLab-V3Trojan/Win32.BuhTrap.R338445
McAfeeGenericRXKB-RP!48B844494A74
MAXmalware (ai score=80)
VBA32BScope.Trojan.Agent
MalwarebytesRansom.Zeppelin
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom.Win32.ZEPPELIN.SMTH
RisingRansom.Zeppelin!1.D4C1 (CLASSIC)
YandexTrojan.GenAsa!CxfKQU+AivY
IkarusTrojan-Ransom.Buran
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Buran.H!tr.ransom
AVGFileRepMalware

How to remove Generic.Ransom.Buhtrap.CEBC38DB?

Generic.Ransom.Buhtrap.CEBC38DB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment