Malware

Application.Babar.273895 removal guide

Malware Removal

The Application.Babar.273895 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Babar.273895 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Application.Babar.273895?


File Info:

name: D161FE4311E862050AB4.mlw
path: /opt/CAPEv2/storage/binaries/6f1af85d98058fed250b92e0fd8aa8f32eff1d86d86c2e5c61a91819b7c3197c
crc32: E3A8AC78
md5: d161fe4311e862050ab4399efbb8e9c9
sha1: 25248d0d92d46eb8006fd94ffa59d65facf1c991
sha256: 6f1af85d98058fed250b92e0fd8aa8f32eff1d86d86c2e5c61a91819b7c3197c
sha512: 489125cd0ad7f4c70b8cc7a2fba8b12f3ddd1a173bf062bd93d317ac2d193d0a52a7270ae1d6756f558505b4c022a6370acd70e6d0ed89e0e73982f0b9c127a4
ssdeep: 6144:R3m9d5PabueGGGGGGGGHGGGGGGGGGGGGGGGGGGGGGGGGGGGGYYwVeZ+JCj1lV3tc:tpuYwVW+Ej1l7r3Mc4dmar
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AB64CF853EA19137FC7A0F3251EEA52BEB14FB9062A1806F63E0FE47BF65101D90C695
sha3_384: 2255bb672221c6f3ade6d969fe05ddfd244969d067d0c79f7c55c2ce7c43222fac06d6130cc772c26d2621627ffb118b
ep_bytes: 81ecd40200005356576a205f33db6801
timestamp: 2016-12-11 15:51:22

Version Info:

CompanyName: Tim Kosse
FileDescription: FileZilla FTP Client
FileVersion: 3.40.0
LegalCopyright: Tim Kosse
OriginalFilename: FileZilla_3.40.0_win32-setup.exe
ProductName: FileZilla
ProductVersion: 3.40.0
Translation: 0x0409 0x04b0

Application.Babar.273895 also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Senoval.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Babar.273895
FireEyeGen:Variant.Application.Babar.273895
SkyhighBehavesLike.Win32.FusionCore.fc
McAfeeRDN/Generic.dx
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Patched.Ve82
K7AntiVirusTrojan ( 005ab4651 )
AlibabaTrojan:Win32/Senoval.03569b2a
K7GWTrojan ( 005ab4651 )
Cybereasonmalicious.311e86
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Patched.NKM
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0DC624
AvastWin32:Patched-AWW [Trj]
ClamAVWin.Malware.Doina-10009055-0
KasperskyVirus.Win32.Senoval.a
BitDefenderGen:Variant.Application.Babar.273895
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentTrojan.Win32.Pathced_ya.16001052
EmsisoftGen:Variant.Application.Babar.273895 (B)
VIPREGen:Variant.Application.Babar.273895
TrendMicroTROJ_GEN.R002C0DC624
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
MAXmalware (ai score=71)
GoogleDetected
VaristW32/Babar.AD.gen!Eldorado
Antiy-AVLGrayWare/Win32.Wacapew
Kingsoftmalware.kb.a.880
MicrosoftTrojan:Win32/Doina.RPX!MTB
XcitiumMalCrypt.Indus!@1qrzi1
ArcabitTrojan.Application.Babar.D42DE7
ZoneAlarmVirus.Win32.Senoval.a
GDataGen:Variant.Application.Babar.273895
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R604111
VBA32BScope.Backdoor.Convagent
ALYacGen:Variant.Application.Babar.273895
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Generic@AI.100 (RDML:5diXdd90drzYd0PtQYbS8w)
IkarusTrojan.Win32.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetAdware/Adware_AGen
AVGWin32:Patched-AWW [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Application.Babar.273895?

Application.Babar.273895 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment