Malware

Application.InstallCore.Babar.444 removal

Malware Removal

The Application.InstallCore.Babar.444 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.InstallCore.Babar.444 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Application.InstallCore.Babar.444?


File Info:

name: A735682CF30C8053A13A.mlw
path: /opt/CAPEv2/storage/binaries/4ceb270a3a69ee43a3da8f549d84bedfb66268d55edbe8466b7744132adecafd
crc32: 0F03F23C
md5: a735682cf30c8053a13a788f43357750
sha1: 0cb344ce09be9aafa13f86bbf19929025aeaf51f
sha256: 4ceb270a3a69ee43a3da8f549d84bedfb66268d55edbe8466b7744132adecafd
sha512: 61cbd26378458c96be90769e6c5c47eecfb6c721d06ce465fa6bc1c3d9ac70f2297f5e56cc8daa49552334f9ffa5ac28ae295113840730138c3fbe6eeef42d50
ssdeep: 12288:tnvpk75XVx83IKKdkaOIL3HQi2o4NCFhEfzIrop7J/4k2dNYvJ2dVO1qJipX:tnvSFV/v/hQiB4NCvGzI6gk2OB2dVlwN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15DD42313F690D071F14299F71C26DC00EB73FA1BC9B9242B769C9A8E4FE3A94521A357
sha3_384: 010c80a6c48617aac26f9bed495e4dcbe47aa7f52f0e40d321d599b8f0a2ac1163338791ee07bd3ae4ab88d0c27b270b
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription:
FileVersion:
LegalCopyright:
ProductName:
ProductVersion:
Translation: 0x0000 0x04b0

Application.InstallCore.Babar.444 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Application.InstallCore.Babar.444
FireEyeGeneric.mg.a735682cf30c8053
CAT-QuickHealPUA.Maxsetup.Gen
SkyhighRDN/Generic PUP.x
McAfeeRDN/Generic PUP.x
MalwarebytesPUP.Optional.InstallCore.DDS
ZillyaAdware.InstallCoreCRTD.Win32.291
SangforSuspicious.Win32.Save.ins
K7AntiVirusUnwanted-Program ( 00575d2f1 )
AlibabaAdWare:Win32/InstallCore.ae6e7cd0
K7GWUnwanted-Program ( 00575d2f1 )
CrowdStrikewin/grayware_confidence_100% (W)
VirITAdware.Win32.InstallCore.LA
SymantecSMG.Heur!gen
Elasticmalicious (high confidence)
ESET-NOD32Win32/InstallCore.Gen.D potentially unwanted
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0OB224
ClamAVWin.Trojan.Generic-9941703-0
Kasperskynot-a-virus:UDS:Downloader.Win32.DealPly.gen
BitDefenderGen:Variant.Application.InstallCore.Babar.444
NANO-AntivirusRiskware.Win32.InstallCore.dfgmcy
AvastFileRepPup [Bundl]
TencentMalware.Win32.Gencirc.10b23ef9
EmsisoftApplication.InstallCore (A)
F-SecurePotentialRisk.PUA/InstallCore.Gen
DrWebTrojan.Packed2.38206
VIPREGen:Variant.Application.InstallCore.Babar.444
TrendMicroTROJ_GEN.R002C0OB224
Trapminemalicious.high.ml.score
SophosInstall Core Click run software (PUA)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Adware.Installcore.Gen
GoogleDetected
AviraPUA/InstallCore.Gen
VaristW32/InstallCore.AG.gen!Eldorado
Kingsoftmalware.kb.a.1000
MicrosoftPUADlManager:Win32/InstallCore
XcitiumApplicUnwnt@#33w4pxr99vf67
ArcabitTrojan.Application.InstallCore.Babar.444
ViRobotAdware.Installcore.626288.MC
ZoneAlarmnot-a-virus:UDS:Downloader.Win32.DealPly.gen
GDataWin32.Application.InstallCore.L
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.BundleInstaller.R346078
VBA32Downware.InstallCore
ALYacGen:Variant.Application.InstallCore.Babar.444
Cylanceunsafe
RisingAdware.InstallCore!1.AB2C (CLASSIC)
YandexPUA.InstallCore!cBnuY9isrJQ
IkarusTrojan.Win32.Injected
MaxSecureAdware.not-a-virus.WIN32.AdWare.DealPly.gen_186490
FortinetRiskware/InstallCore
AVGFileRepPup [Bundl]
DeepInstinctMALICIOUS

How to remove Application.InstallCore.Babar.444?

Application.InstallCore.Babar.444 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment