Ransom Trojan

Trojan.Ransom.BUO removal instruction

Malware Removal

The Trojan.Ransom.BUO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.BUO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.Ransom.BUO?


File Info:

crc32: DCB16DE9
md5: d02ccf9c8c581975060708af0813d209
name: D02CCF9C8C581975060708AF0813D209.mlw
sha1: c5a2353138eeff89c64fd8fdab543c7cfa4115e1
sha256: 129eb720e23977765a67a1d673f7354b8f39a578126e62e3b5f9f6fec525aafc
sha512: 3477e4d938d68f7f0358cbbc8a1fc2fa9ea1395ff5f4c3b3a0425151491aa2d2b97fdd37ecd98d8a2ce3f7865e3155e2541b80b1906c7c00c9789dbb1581376b
ssdeep: 12288:S7DxagFeZvl8ZVjhGJc0cqRpEc0Tk2Et3afCnCSQps/:S71agFgLJc0c0SEpafChQW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Ransom.BUO also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005190011 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
ClamAVWin.Ransomware.Nymaim-9770095-0
CAT-QuickHealTrojan.GenericRI.S16230134
ALYacTrojan.Ransom.BUO
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanDownloader:Win32/Nymaim.1ec52324
K7GWTrojan ( 005190011 )
Cybereasonmalicious.c8c581
CyrenW32/Agent.APD.gen!Eldorado
ESET-NOD32Win32/TrojanDownloader.Nymaim.BA
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.BUO
NANO-AntivirusTrojan.Win32.Cryptoff.etisfs
MicroWorld-eScanTrojan.Ransom.BUO
TencentMalware.Win32.Gencirc.10b9bd3a
Ad-AwareTrojan.Ransom.BUO
ComodoTrojWare.Win32.Ransom.Tiggre.A@7b1og1
DrWebTrojan.Siggen7.30668
ZillyaTrojan.Ransom.Win32.955
TrendMicroRansom_CERBER.SMALY0
FireEyeGeneric.mg.d02ccf9c8c581975
SophosML/PE-A + Mal/Elenoocka-E
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Cryptoff.dp
AviraHEUR/AGEN.1116778
ArcabitTrojan.Ransom.BUO
ZoneAlarmHEUR:Trojan.Win32.Generic
TACHYONRansom/W32.Cryptoff.501760.E
AhnLab-V3Trojan/Win32.Cryptoff.C2182035
Acronissuspicious
McAfeeRansomware-GFS!D02CCF9C8C58
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Cryptoff
MalwarebytesTrojan.Nymaim
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.100 (RDML:WYxMLsQjIG4y1KRBbiJcog)
YandexTrojan.GenAsa!QWqOgB00tPU
IkarusTrojan-Downloader.Nymaim
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.CQXJ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HxQBuX8A

How to remove Trojan.Ransom.BUO?

Trojan.Ransom.BUO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment