Ransom Trojan

Should I remove “Trojan.Ransom.Babuk.A”?

Malware Removal

The Trojan.Ransom.Babuk.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.Babuk.A virus can do?

  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Ransom.Babuk.A?


File Info:

crc32: 45F56344
md5: a69951d0cb10d5ccfb604400f4e82924
name: A69951D0CB10D5CCFB604400F4E82924.mlw
sha1: 306ab3caad66a773c25f8871ef8ee79f09625adf
sha256: 55ca818548d35fe757e378edb1e5cb857bb39283bfce0952890bf0a25f56759e
sha512: 26a4c60ba934c862e6da7464bbfb09b8ee1d276d63d775f2546ed64b226bfc32a5fde030ce91cc1bc57516807f688c1e4bb3e28569730879d121453255adee3a
ssdeep: 1536:/6UhZM4hubesrQLOJgY8ZZP8LHD4XWaNH71dLdG1iiFM2iG2zs4:jhZ5YesrQLOJgY8Zp8LHD4XWaNH71dL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Ransom.Babuk.A also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005782fe1 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen12.62665
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Babuk.A
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Babuk.2ffa92fd
K7GWTrojan ( 005782fe1 )
Cybereasonmalicious.0cb10d
CyrenW32/Babyk.A.gen!Eldorado
SymantecRansom.Babuk
ESET-NOD32a variant of Win32/Filecoder.Babyk.A
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Maze-7473772-0
KasperskyTrojan-Ransom.Win32.Babuk.a
BitDefenderTrojan.Ransom.Babuk.A
NANO-AntivirusTrojan.Win32.Ransom.iuaipi
ViRobotTrojan.Win32.Ransom.80896.E
MicroWorld-eScanTrojan.Ransom.Babuk.A
Ad-AwareTrojan.Ransom.Babuk.A
SophosML/PE-A + Troj/Ransom-GGD
BitDefenderThetaGen:NN.ZexaF.34790.euW@aWBl0ug
TrendMicroRansom.Win32.BABUK.SMRD1
McAfee-GW-EditionGenericRXNS-AS!A69951D0CB10
FireEyeGeneric.mg.a69951d0cb10d5cc
EmsisoftTrojan.FileCoder (A)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.EPACK.Gen2
MicrosoftRansom:Win32/BabukCrypt.PB!MTB
ArcabitTrojan.Ransom.Babuk.A
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataTrojan.Ransom.Babuk.A
TACHYONRansom/W32.BabukLocker.80896.B
AhnLab-V3Ransomware/Win.Babuk.R428564
Acronissuspicious
McAfeeGenericRXNS-AS!A69951D0CB10
MAXmalware (ai score=84)
VBA32BScope.TrojanRansom.Gen
MalwarebytesRansom.Babuk
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.BABUK.SMRD1
RisingRansom.Babuk!1.D7A0 (CLASSIC)
IkarusTrojan-Ransom.Babyk
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/FilecoderProt.F183!tr.ransom
AVGWin32:Malware-gen
Qihoo-360HEUR/QVM20.1.6985.Malware.Gen

How to remove Trojan.Ransom.Babuk.A?

Trojan.Ransom.Babuk.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment