Malware

Babar.106469 information

Malware Removal

The Babar.106469 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.106469 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the Tofsee malware family
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Babar.106469?


File Info:

name: 112B99145085F48E87D5.mlw
path: /opt/CAPEv2/storage/binaries/39fc451e2ed11878c5a182c3fd1200d3d7dc0d2e66d77cfc35672aabbaf8853c
crc32: C190DBF3
md5: 112b99145085f48e87d53323b6d39c9c
sha1: a6d47764f22e39a171cc9ff27baa0e5cbcd69ad7
sha256: 39fc451e2ed11878c5a182c3fd1200d3d7dc0d2e66d77cfc35672aabbaf8853c
sha512: eab8c887a8eaa03b8b4cc264e5918f03f7d2a7572ff49f7bf60ad65763ba4619dbe8b76aa4464ac52c3a0a8d3dd9e597e97c10abbde1481598a582dbbdb4b913
ssdeep: 6144:QxLSC/id74hVdJVFVFVFVFVFVFVFVFVFVFVFVFVFVFVFVFVFVFVFVFVFVFVFVFVL:sh/idchVd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T175B69DC073B1F84DE2328571B926DBFA95656C269522170B374BBF0FBC31211AEDE192
sha3_384: d40ee820243ea4c0e4e2b8871d33d199807feda4912f014220ec5be004986c053976e2a715619699aa6421e4638e2470
ep_bytes: e8ac360000e979feffff8bff558bec83
timestamp: 2022-01-27 15:33:12

Version Info:

Translations: 0x0179 0x00aa

Babar.106469 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.106469
ClamAVWin.Packed.Botx-9971431-0
FireEyeGeneric.mg.112b99145085f48e
McAfeePacked-GEE!112B99145085
CylanceUnsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.4f22e3
CyrenW32/Kryptik.GNZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HQXW
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.Win32.Tofsee.gen
BitDefenderGen:Variant.Babar.106469
AvastWin32:RansomX-gen [Ransom]
Ad-AwareGen:Variant.Babar.106469
EmsisoftGen:Variant.Babar.106469 (B)
TrendMicroMal_Tofsee
McAfee-GW-EditionBehavesLike.Win32.Generic.vm
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Tofsee.kotzq
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASCommon.2BA
ArcabitTrojan.Babar.D19FE5
ZoneAlarmHEUR:Backdoor.Win32.Tofsee.gen
GDataWin32.Trojan.PSE.FY3WE6
GoogleDetected
AhnLab-V3Packed/Win.GEE.R522618
Acronissuspicious
ALYacGen:Variant.Babar.106469
VBA32Malware-Cryptor.2LA.gen
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallMal_Tofsee
RisingTrojan.Generic@AI.100 (RDML:IV8s1D6zs4bQQeKLfSdTVg)
IkarusTrojan.Win32.Azorult
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Ursnif.BCED!tr
AVGWin32:RansomX-gen [Ransom]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Babar.106469?

Babar.106469 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment