Ransom

How to remove “Ransom.Babuk.46”?

Malware Removal

The Ransom.Babuk.46 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Babuk.46 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Ukrainian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the Raccoon malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Ransom.Babuk.46?


File Info:

name: A969E646564A7486D537.mlw
path: /opt/CAPEv2/storage/binaries/84e28f75b67b5896e3c7302b9b330ac41ffe68249ee7154c762c45096dbdf1bd
crc32: 5E4085D4
md5: a969e646564a7486d5376a31c7733cd1
sha1: f6b2fb20af1bb4b083cd91ead340b61e0e123973
sha256: 84e28f75b67b5896e3c7302b9b330ac41ffe68249ee7154c762c45096dbdf1bd
sha512: 5cb16672484f738fff301d677fd451775c3abdf00296b3ec1b9ed32a7d4bf78299f39ad8c8dadeadcbdfcaf34341e9f63583eaad470d47ec4c633d95153db7ae
ssdeep: 12288:/EsdnJA7BS915mIw3dUzbJwzToDrhHyWRUJvlXsd9rI4BJDoBayz:bdnO1ST5Y3+zbJEGrhHypJtXs7I4+a
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CBC412C69B4769B3E0A8193189B7D4553525740BFB3A30E39E3AFAEF5E39493004D60A
sha3_384: b73523159250dec2adc108470b336f28b6b5fb811520ca6655d23113f609d7e9d686f91935c1f477b28137f2b180fec4
ep_bytes: 60be0020d5048dbe00f06afb57eb0b90
timestamp: 2020-01-19 20:17:58

Version Info:

FileVersions: 1.0.5.9
InternalSurname: vebuk.ekc
LegalCo: Copyri (C) 2019, pirmudationca
Prod: 1.2.8

Ransom.Babuk.46 also known as:

BkavW32.AIDetectMalware
LionicHacktool.Win32.Shellcode.3!c
MicroWorld-eScanGen:Variant.Ransom.Babuk.46
ClamAVWin.Packed.Glupteba-9821452-1
FireEyeGeneric.mg.a969e646564a7486
McAfeeArtemis!A969E646564A
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00575f941 )
AlibabaTrojan:Win32/Stealer.01f0df95
K7GWTrojan ( 00575f941 )
Cybereasonmalicious.6564a7
BitDefenderThetaGen:NN.ZexaF.36196.HmGfaasWTEfI
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik.HITY
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Exploit.Win32.ShellCode.Agent.pef
BitDefenderGen:Variant.Ransom.Babuk.46
AvastWin32:BotX-gen [Trj]
TencentWin32.Exploit.Shellcode.Iajl
EmsisoftGen:Variant.Ransom.Babuk.46 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebTrojan.PWS.Stealer.29826
VIPREGen:Variant.Ransom.Babuk.46
McAfee-GW-EditionBehavesLike.Win32.Lockbit.hc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Ransom.Babuk.46
JiangminExploit.ShellCode.bhu
AviraTR/Crypt.XPACK.Gen7
MAXmalware (ai score=85)
Antiy-AVLTrojan[Exploit]/Win32.ShellCode
ArcabitTrojan.Ransom.Babuk.46
ZoneAlarmHEUR:Exploit.Win32.ShellCode.Agent.pef
MicrosoftTrojan:Win32/Stealer.MT!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.RL_Agent.R363286
Acronissuspicious
VBA32BScope.Trojan.Azorult
ALYacGen:Variant.Ransom.Babuk.46
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/GdSda.A
RisingTrojan.Kryptik!8.8 (TFE:5:c4Dvue7LbZD)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HJCJ!tr
AVGWin32:BotX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom.Babuk.46?

Ransom.Babuk.46 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment