Malware

About “Babar.194139” infection

Malware Removal

The Babar.194139 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.194139 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Babar.194139?


File Info:

name: A75B9AA5828F92211094.mlw
path: /opt/CAPEv2/storage/binaries/076d40c14fda75453cc00cfc2dd7ca743d10b466625e0bfa7f30cecc7f342b3f
crc32: FC6FCA80
md5: a75b9aa5828f92211094030cc7020e14
sha1: 9db4f1334599abb2c14661028a5547d57c9c35d0
sha256: 076d40c14fda75453cc00cfc2dd7ca743d10b466625e0bfa7f30cecc7f342b3f
sha512: 1213326d348cc5e59220548e01f5a9d65525d78eebba2ccc1c9908b270412ccd0869dc3379ee27b4362889eb0dd285795eddca489f7f95d42d589f1a80aaaebb
ssdeep: 1536:inPIbiThZjV8hvbGzUtiTgCpGWNAM7KYksPrEdpglV55uhuaK1gcJtB88888888f:inPIbiThZjqhnwGWqGK8PrEdpg355uhq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17293291273D30070F866AE75CD6AC4444E3ABD652D36902E3AF4EA0D9C75FC6D84BB92
sha3_384: face525ccb3044205266cdde8d4871da48805ad6cafeca2e8293174fa116f309cde73edebbf55209d0a7f9407e0b3501
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2014-07-09 07:58:13

Version Info:

0: [No Data]

Babar.194139 also known as:

LionicTrojan.Win32.Babar.4!c
MicroWorld-eScanGen:Variant.Babar.194139
McAfeeArtemis!A75B9AA5828F
SangforTrojan.Win32.Agent.Vkzh
CrowdStrikewin/grayware_confidence_100% (W)
CyrenW32/Agent.FTP.gen!Eldorado
Elasticmalicious (moderate confidence)
BitDefenderGen:Variant.Babar.194139
EmsisoftGen:Variant.Babar.194139 (B)
VIPREGen:Variant.Babar.194139
McAfee-GW-EditionBehavesLike.Win32.Generic.nm
Trapminemalicious.moderate.ml.score
FireEyeGen:Variant.Babar.194139
GDataGen:Variant.Babar.194139
Antiy-AVLGrayWare/Win32.Wacapew
ArcabitTrojan.Babar.D2F65B
GoogleDetected
ALYacGen:Variant.Babar.194139
MAXmalware (ai score=89)
TrendMicro-HouseCallTROJ_GEN.R002H09EB23
RisingTrojan.Generic@AI.94 (RDMK:cmRtazrTD7wf3uOleHyNoYDus0WI)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CorruptRopf.S!dam
DeepInstinctMALICIOUS

How to remove Babar.194139?

Babar.194139 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment