Ransom

Ransom:Win32/Babuk.MK!MTB malicious file

Malware Removal

The Ransom:Win32/Babuk.MK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Babuk.MK!MTB virus can do?

  • Authenticode signature is invalid
  • CAPE detected the Babuk malware family

How to determine Ransom:Win32/Babuk.MK!MTB?


File Info:

name: BC4D60AC964C2E201F5E.mlw
path: /opt/CAPEv2/storage/binaries/665666024f8075ad32c414b6b33720beb5160f7887b7834d821cda117af8e0ba
crc32: E28F7B56
md5: bc4d60ac964c2e201f5ed999764cbf57
sha1: 4b4befb5a17a5b6f2056ecdd199af41ddf85239e
sha256: 665666024f8075ad32c414b6b33720beb5160f7887b7834d821cda117af8e0ba
sha512: 8e58f803e56b3f5eefad847b731e1d0ad6937893ab134e42255b9c82071600ca0da8d68fa178bc4361911c56e33117f139dabebe84247c05a1dc7234d8ba87e4
ssdeep: 1536:QHSAhZMvhumvHlosrQLOJgY8ZZPqHD4xdLdG1iiFM2iG2uX:+hZ2tesrQLOJgY8ZpqHD4xdLdG1iiFM8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10363C9116D45E3B5C5D172319113E1EAC53A2A7043B5B28B63C017AEFE10AE8E6BCF67
sha3_384: 3aa7a2b65d2d322e1debc4af4572c2496c2ef6ec27457c58b1e31c9b884f34dc329b922dac271e44b9940a08a7487ed5
ep_bytes: 558bec81ec90000000e812520000e8ad
timestamp: 2021-02-23 11:12:08

Version Info:

0: [No Data]

Ransom:Win32/Babuk.MK!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.34363
ClamAVWin.Ransomware.Packer-7473772-1
CAT-QuickHealRansom.Babuk.S19047450
ALYacGeneric.Ransom.Babuk.A.F5374AE9
MalwarebytesRansom.FileCryptor
BitDefenderGeneric.Ransom.Babuk.A.F5374AE9
SymantecRansom.Babuk
APEXMalicious
CynetMalicious (score: 100)
ViRobotTrojan.Win32.Ransom.76800.C
MicroWorld-eScanGeneric.Ransom.Babuk.A.F5374AE9
RisingRansom.Babuk!1.D7A0 (CLASSIC)
Ad-AwareGeneric.Ransom.Babuk.A.F5374AE9
SophosML/PE-A
TrendMicroRansom.Win32.BABUKLOCKER.SM
McAfee-GW-EditionGenericRXNS-AS!BC4D60AC964C
FireEyeGeneric.mg.bc4d60ac964c2e20
EmsisoftGeneric.Ransom.Babuk.A.F5374AE9 (B)
IkarusTrojan-Ransom.Babyk
GDataWin32.Trojan-Ransom.Babuk.A
JiangminTrojan.Agent.ddss
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASCommon.207
ArcabitGeneric.Ransom.Babuk.A.F5374AE9
MicrosoftRansom:Win32/Babuk.MK!MTB
AhnLab-V3Ransomware/Win.Babuk.R428564
McAfeeGenericRXNS-AS!BC4D60AC964C
VBA32Malware-Cryptor.Win32.General.4
TrendMicro-HouseCallRansom.Win32.BABUKLOCKER.SM
FortinetW32/FilecoderProt.F183!tr.ransom
Cybereasonmalicious.c964c2
MaxSecureTrojan.Malware.121218.susgen

How to remove Ransom:Win32/Babuk.MK!MTB?

Ransom:Win32/Babuk.MK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment