Ransom

Should I remove “Ransom.Babuk.86 (B)”?

Malware Removal

The Ransom.Babuk.86 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Babuk.86 (B) virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Ransom.Babuk.86 (B)?


File Info:

name: 6EABD860D7A3C2D8987E.mlw
path: /opt/CAPEv2/storage/binaries/a121e5a57d1cc9f6bb04cbce2fa8d94109e550f6ad301ed928ffa796e51f133d
crc32: 5848FD47
md5: 6eabd860d7a3c2d8987edd5ef03c0cef
sha1: dd193543efa493c200798bcc8ca809312a4469f4
sha256: a121e5a57d1cc9f6bb04cbce2fa8d94109e550f6ad301ed928ffa796e51f133d
sha512: ff8e3ebffb24c0fbe108637d720304035ca98a8ac3bef36174f49bedffdac5daaa61e0c0b66bfe6d1d5f707ff78daef8182de9eac27199e0b481cdb032578b5e
ssdeep: 12288:TWUYjx80eZzKwvqMlkl0a04OL5a6MuJpE0Lny19c09IkjrVIqbh/Uh9:Mi0QzKwv80a04OL5a6MuJpE0Lny19c0k
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B2847E5BB3840372D6E20372358E99C1BF2EAC7B637582916468A11D2377F6483BB7D1
sha3_384: 73afecfe5ec69b910e95e949b192976b786bf8925f748d76d7a234323852fb26b6934c396db8223fe2c1b00f310b4712
ep_bytes: 60ba000000008aa20010400080ecba80
timestamp: 2004-09-05 06:27:43

Version Info:

CompanyName: TODO:
FileDescription: TODO:
FileVersion: 1.0.0.1
InternalName: AdwTest.exe
LegalCopyright: TODO: (c) . All rights reserved.
OriginalFilename: AdwTest.exe
ProductName: TODO:
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04e4

Ransom.Babuk.86 (B) also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Babuk.86
ClamAVWin.Malware.Razy-9759519-0
SkyhighBehavesLike.Win32.Generic.fh
McAfeeGenericRXOB-DF!6EABD860D7A3
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005ac2dd1 )
K7GWTrojan ( 004b494b1 )
Cybereasonmalicious.3efa49
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Agent.WTK
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agent.antno
BitDefenderGen:Variant.Ransom.Babuk.86
NANO-AntivirusTrojan.Win32.Patched.foubml
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Agent.zl
SophosMal/Agent-AWE
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.MulDrop5.42246
ZillyaTrojan.AgentGen.Win32.95
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.6eabd860d7a3c2d8
EmsisoftGen:Variant.Ransom.Babuk.86 (B)
IkarusTrojan.Win32.Aenjaris
GDataWin32.Trojan.BadJoke.J
GoogleDetected
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Agent.wtk
Kingsoftmalware.kb.a.989
ArcabitTrojan.Ransom.Babuk.86
ZoneAlarmHEUR:Trojan.Win32.Nobady.gen
MicrosoftTrojan:Win32/Aenjaris.AL!bit
VaristW32/Babuk.A.gen!Eldorado
AhnLab-V3Trojan/Win.DF.C5535790
VBA32SScope.Malware-Cryptor.Aenjaris
ALYacGen:Variant.Ransom.Babuk.86
MAXmalware (ai score=81)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Agent!1.A728 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.WTK!tr
BitDefenderThetaGen:NN.ZexaF.36744.yu3@aC8QXyki
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Ransom.Babuk.86 (B)?

Ransom.Babuk.86 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment