Ransom

Ransom.Babuk.67 removal guide

Malware Removal

The Ransom.Babuk.67 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Babuk.67 virus can do?

  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Manipulates data from or to the Recycle Bin
  • Authenticode signature is invalid
  • Exhibits possible ransomware file modification behavior
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools

How to determine Ransom.Babuk.67?


File Info:

name: 7E3D84C4EEE09177E20E.mlw
path: /opt/CAPEv2/storage/binaries/dcebacbc508ebfa30ad9c0fdb20916f7e62a11616d3379e820d612295938c5fe
crc32: 4B2A0389
md5: 7e3d84c4eee09177e20e3ded8ae39684
sha1: 01dd19a4a4b3bbe528da8e8d48fcf4f3d5a0a13b
sha256: dcebacbc508ebfa30ad9c0fdb20916f7e62a11616d3379e820d612295938c5fe
sha512: 9a335e5cfd5b9bf75a8e77c27212c0d00f21aa178854ee7a7d09d927a51d4fc720edddf0c1a916f978529a5c85ae47dcf16e5ae7bba3ec726699818fe9272414
ssdeep: 1536:jwG6++mq1sA1jB5gJsifsrQLOJgY8ZZP8LHD4XWaNH71dLdG1iiFM2iG2xyqM8E1:0f++mqOAhB5gJtsrQLOJgY8Zp8LHD4Xr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C36385116B45E6B6D5912170811BF1B6C23A097003F162A7A7C11BBBFB256B8E37DF23
sha3_384: abf25f473c849750a27499c8575a1c907842e77e1c89f58c614382c44e4696e96a9e555a2e5cddc123539c1b4ff37636
ep_bytes: 558bec81ec94000000a1a410410033c5
timestamp: 2022-04-29 06:12:47

Version Info:

0: [No Data]

Ransom.Babuk.67 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Babuk.67
FireEyeGeneric.mg.7e3d84c4eee09177
McAfeeGenericRXQL-KE!7E3D84C4EEE0
Cybereasonmalicious.4eee09
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Ransomware.Packer-7473772-1
BitDefenderGen:Variant.Ransom.Babuk.67
AvastWin32:RansomX-gen [Ransom]
Ad-AwareGen:Variant.Ransom.Babuk.67
EmsisoftGen:Variant.Ransom.Babuk.67 (B)
F-SecureTrojan.TR/Dropper.Gen
VIPREGen:Variant.Ransom.Babuk.67
McAfee-GW-EditionBehavesLike.Win32.Upatre.km
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Ransom.Babuk.67
JiangminGeneric.Ransom.b
AviraTR/Dropper.Gen
MicrosoftRansom:Win32/Babuk.ECCP!MTB
CynetMalicious (score: 100)
AhnLab-V3Ransomware/Win.Maze.R473427
ALYacGen:Variant.Ransom.Babuk.67
MAXmalware (ai score=82)
VBA32BScope.Trojan.Encoder
MalwarebytesMalware.AI.3155384457
RisingTrojan.Generic@AI.97 (RDML:4WZraxOcNLqw/o4esjJF8A)
FortinetW32/Babuk.KE!tr.ransom
BitDefenderThetaAI:Packer.AB808F7C1E
AVGWin32:RansomX-gen [Ransom]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Ransom.Babuk.67?

Ransom.Babuk.67 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment