Ransom

Generic.Ransom.Buhtrap.E79F8D2B removal instruction

Malware Removal

The Generic.Ransom.Buhtrap.E79F8D2B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Buhtrap.E79F8D2B virus can do?

  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Code injection with CreateRemoteThread in a remote process
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
geoiptool.com
a.tomx.xyz
www.geodatatool.com
ocsp.comodoca.com
ocsp.usertrust.com
crl.usertrust.com

How to determine Generic.Ransom.Buhtrap.E79F8D2B?


File Info:

crc32: A3B7914A
md5: 78412982e79e768a6788c578488c6c31
name: 78412982E79E768A6788C578488C6C31.mlw
sha1: 97854768929a1c29bcd3fa1b9b37b490672951aa
sha256: 3b563b41d048003ee5db507416c4bb288bb5751e6093fdcaaba59605d18cbb38
sha512: cd3595419911ef7130ed1d150968ae9b6a27a934dd5a66427fa90a5badcfede427a008d2bd02d4b08ef8a608e94a593b4d1f948f073e74e0bd8541a4b91a3aee
ssdeep: 3072:7ZteClhyMPRRqJBgXqh9iAUxF4uGUq2tE:7ZEClhyMmL9xm4FOtE
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic.Ransom.Buhtrap.E79F8D2B also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055b3591 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.33062
CynetMalicious (score: 100)
ALYacTrojan.Ransom.VegaLocker
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 0055b3591 )
Cybereasonmalicious.2e79e7
CyrenW32/Ransom.IHVZ-2003
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Buran.J
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderGeneric.Ransom.Buhtrap.E79F8D2B
NANO-AntivirusTrojan.Win32.Encoder.idpqzx
MicroWorld-eScanGeneric.Ransom.Buhtrap.E79F8D2B
TencentWin32.Trojan.Raas.Auto
Ad-AwareGeneric.Ransom.Buhtrap.E79F8D2B
SophosMal/Generic-R + Mal/Behav-010
ComodoMalware@#2a79j7asx72zo
BitDefenderThetaAI:Packer.D4E784401E
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.ZEPPELIN.SMTH
McAfee-GW-EditionBehavesLike.Win32.Worm.hz
FireEyeGeneric.mg.78412982e79e768a
EmsisoftGeneric.Ransom.Buhtrap.E79F8D2B (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Worm.Gen
AviraTR/ATRAPS.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/LockBit.PA!MTB
GDataGeneric.Ransom.Buhtrap.E79F8D2B
AhnLab-V3Malware/Win32.Generic.C4224454
McAfeeArtemis!78412982E79E
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Crypmod
MalwarebytesRansom.FileCryptor
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.ZEPPELIN.SMTH
RisingRansom.Zeppelin!8.1155D (CLOUD)
YandexTrojan.Agent!cNOvZRmj22c
IkarusTrojan-Ransom.Buran
MaxSecureTrojan.Malware.771626.susgen
FortinetW32/Buran.H!tr.ransom
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Generic.Ransom.Buhtrap.E79F8D2B?

Generic.Ransom.Buhtrap.E79F8D2B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment