Ransom

Ransom:Win32/Buhtrap!MTB (file analysis)

Malware Removal

The Ransom:Win32/Buhtrap!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Buhtrap!MTB virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ransom:Win32/Buhtrap!MTB?


File Info:

crc32: 0057586E
md5: 9dc15f09419004c55a487381f4765e97
name: 9DC15F09419004C55A487381F4765E97.mlw
sha1: 191efae79d0586f60e077c0387f7acac802a4bc7
sha256: 13a940ac4fb1ac472c8706986a3059658426cbada00cb8327577e08d9397e724
sha512: 657c0fa222985600c8a9b232d00ec5b644b529c333861610f9ef62dce83524568114f83cde8a71b187797ed586a9dfabf73673884656b7576264ce4ccbe15eed
ssdeep: 6144:9GE9Ogt/d8W/PDoGm2fRtu5022W8B1EhZADnndkBfi2ADdSRb:jbtRboGpG50xWq1EXyndOfi2AEp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Buhtrap!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0049f6ae1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.27282
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.31760434
CylanceUnsafe
ZillyaTrojan.Lolopak.Win32.37
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaRansom:Win32/Buhtrap.6598017e
K7GWRiskware ( 0049f6ae1 )
Cybereasonmalicious.941900
CyrenW32/Trojan.UMLY-5477
SymantecTrojan Horse
ESET-NOD32Win32/Filecoder.Buran.B
ZonerTrojan.Win32.85826
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyTrojan.Win32.Lolopak.tu
BitDefenderTrojan.GenericKD.31760434
NANO-AntivirusTrojan.Win32.Encoder.fnmwby
MicroWorld-eScanTrojan.GenericKD.31760434
TencentWin32.Trojan.Lolopak.Hxzt
Ad-AwareTrojan.GenericKD.31760434
SophosMal/Generic-S + Mal/Generic-L
ComodoMalware@#1yx7s8z6kbs0x
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.USMGAHAL
McAfee-GW-EditionGenericRXHA-MO!9DC15F094190
FireEyeGeneric.mg.9dc15f09419004c5
EmsisoftMalCert.B (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Lolopak.dg
AviraTR/Crypt.XPACK.VM
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2AB3B24
MicrosoftRansom:Win32/Buhtrap!MTB
AegisLabTrojan.Win32.Lolopak.4!c
GDataWin32.Trojan.Agent.QKDS7L
AhnLab-V3Trojan/Win32.Lolopak.C3575065
McAfeeGenericRXHA-MO!9DC15F094190
VBA32BScope.Trojan.Fuerboos
PandaTrj/WLT.E
TrendMicro-HouseCallTROJ_GEN.USMGAHAL
RisingSpyware.Stealer!8.3090 (KTSE)
IkarusTrojan-Ransom.Buran
FortinetW32/Kryptik.GPXX!tr.ransom
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml

How to remove Ransom:Win32/Buhtrap!MTB?

Ransom:Win32/Buhtrap!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment