Ransom

Ransom.Babuk.S22456537 removal tips

Malware Removal

The Ransom.Babuk.S22456537 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Babuk.S22456537 virus can do?

  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom.Babuk.S22456537?


File Info:

crc32: ABAAAEBC
md5: bff0b3b605daa1e93256305c7d2dace8
name: BFF0B3B605DAA1E93256305C7D2DACE8.mlw
sha1: 2a2eb69c25742194ff7b0366275f1c4b5ce6c0b8
sha256: 7e9280e02d633ed665843dff410f99a587fcec2498ed4681ae63d177a0a46e20
sha512: d5b8fd1b771c7efa810dea90d67dc653e38ca13b98e0eb7f262819f46146dba67b12506601b023ba09995cedb349a16b7f683a634d01d2f704072255330c77aa
ssdeep: 1536:q6UhZM4hubesrQLOJgY8ZZP8LHD4XWaNH71dLdG1iiFM2iG2zs4:0hZ5YesrQLOJgY8Zp8LHD4XWaNH71dL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.Babuk.S22456537 also known as:

K7AntiVirusTrojan ( 005782fe1 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen12.62665
CynetMalicious (score: 100)
CAT-QuickHealRansom.Babuk.S22456537
ALYacTrojan.Ransom.Babuk.A
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 005782fe1 )
Cybereasonmalicious.605daa
CyrenW32/Ransom.PS.gen!Eldorado
SymantecRansom.Babuk
ESET-NOD32a variant of Win32/Filecoder.Babyk.A
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Maze-7473772-0
KasperskyTrojan-Ransom.Win32.Babuk.a
BitDefenderTrojan.Ransom.Babuk.A
NANO-AntivirusTrojan.Win32.Ransom.iuaipi
ViRobotTrojan.Win32.Ransom.80896.E
MicroWorld-eScanTrojan.Ransom.Babuk.A
TencentMalware.Win32.Gencirc.10ce690d
Ad-AwareTrojan.Ransom.Babuk.A
SophosML/PE-A + Troj/Ransom-GGD
BitDefenderThetaGen:NN.ZexaF.34170.euW@aWBl0ug
TrendMicroRansom.Win32.BABUK.SMRD1
McAfee-GW-EditionBehavesLike.Win32.Generic.lm
FireEyeGeneric.mg.bff0b3b605daa1e9
EmsisoftTrojan.FileCoder (A)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.EPACK.Gen2
MicrosoftRansom:Win32/Babuk.MAK!MTB
GDataWin32.Trojan-Ransom.Filecoder.2AT5IW@gen
TACHYONRansom/W32.BabukLocker.80896.B
AhnLab-V3Ransomware/Win.Babuk.R428564
Acronissuspicious
McAfeeGenericRXNS-AS!BFF0B3B605DA
MAXmalware (ai score=88)
VBA32BScope.TrojanRansom.Crypmod
MalwarebytesRansom.Babuk
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.BABUK.SMRD1
RisingRansom.Babuk!1.D7A0 (CLASSIC)
IkarusTrojan-Ransom.Babyk
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/FilecoderProt.F183!tr.ransom
AVGWin32:Malware-gen

How to remove Ransom.Babuk.S22456537?

Ransom.Babuk.S22456537 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment