Ransom

Ransom.Babuk removal tips

Malware Removal

The Ransom.Babuk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Babuk virus can do?

  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom.Babuk?


File Info:

crc32: 9641E706
md5: ebe7bf69eceb80d155d7a16b8c61e15c
name: EBE7BF69ECEB80D155D7A16B8C61E15C.mlw
sha1: 5c8b0a23360420c33fb89e100fb996215a795a1f
sha256: 678bfbf5d73d6cf38532e11b11dbed17668d94711e2e2ea27311dd46490201b7
sha512: 76b0bb1a5a0fb0e90c06a8f6448a3116789788c5c35fab9f64a9122665a5a579d8336699a90cdb1db540395d6a37f107171440a4be6a84b6afa34fe69cecbbff
ssdeep: 1536:jS5hiBMAMnL+by+PGuMsrQLOJgY8ZZP8LHD4XWaNH71dLdG1iiFM2iG2es4:jS/iBMAqeyXBsrQLOJgY8Zp8LHD4XWa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.Babuk also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Encoder.33684
CynetMalicious (score: 100)
ALYacGen:Heur.Ransom.REntS.Gen.1
CylanceUnsafe
Cybereasonmalicious.9eceb8
CyrenW32/Babyk.A.gen!Eldorado
SymantecRansom.Babuk
ESET-NOD32a variant of Win32/Filecoder.Babyk.A
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Maze-7473772-0
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderGen:Heur.Ransom.REntS.Gen.1
NANO-AntivirusTrojan.Win32.Ransom.iqymjq
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
Ad-AwareGen:Heur.Ransom.REntS.Gen.1
SophosML/PE-A + Troj/Ransom-GGD
BitDefenderThetaGen:NN.ZexaF.34678.euW@aePG5Fd
McAfee-GW-EditionGenericRXNS-AS!EBE7BF69ECEB
FireEyeGeneric.mg.ebe7bf69eceb80d1
EmsisoftTrojan.FileCoder (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agent.dfxx
MicrosoftRansom:Win32/Babuk.SIB!MTB
ArcabitTrojan.Ransom.REntS.Gen.1
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataWin32.Trojan-Ransom.Babuk.A
TACHYONRansom/W32.BabukLocker.80896
AhnLab-V3Trojan/Win32.BabukRansom.C4337300
Acronissuspicious
McAfeeGenericRXNS-AS!EBE7BF69ECEB
MAXmalware (ai score=81)
VBA32BScope.TrojanRansom.Gen
MalwarebytesRansom.Babuk
PandaTrj/GdSda.A
RisingRansom.Generic!8.E315 (TFE:3:Wlxq2duDPiR)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/FilecoderProt.F183!tr.ransom
AVGWin32:Malware-gen

How to remove Ransom.Babuk?

Ransom.Babuk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment