Malware

Babar.109697 malicious file

Malware Removal

The Babar.109697 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.109697 virus can do?

  • HTTPS urls from behavior.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Babar.109697?


File Info:

name: 525951731B3C6DFD38CC.mlw
path: /opt/CAPEv2/storage/binaries/466b495b9f267f428e651785a5443f3e9d8ab49fb0ed1a0ac180b9f94b0f7fd0
crc32: 0FF3F52E
md5: 525951731b3c6dfd38ccdd3241d6b620
sha1: e0e049c86ce8c1928d1fd9c74ae11dc9ce4ef609
sha256: 466b495b9f267f428e651785a5443f3e9d8ab49fb0ed1a0ac180b9f94b0f7fd0
sha512: b61f55eabffae50ffb47eff6a58dc36317b8f5601d8538a6bc9e783209c6252468ae618afee0ee0870caad86e2f5b9675c5962575544a0cde02d3d79ed952f54
ssdeep: 3072:4v92oYuqc/FMPIYIeHZ/XE9d+8INRjbJdTJRTqfPcCEd:ysovqcGPIYZ/XE9bcRjZcHbw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16BF36B397681C073D99710349AF9C7B65A7EB8710B61A4C7B7D50B396E702E2A73830B
sha3_384: f37976a19c2c8e2887ac4e02f8520600f4d5f7ec687eb851ec03c2f02b10b4162240b8ef803af017639ef94852b22737
ep_bytes: e89ea80000e989feffffff3534744200
timestamp: 2022-12-19 00:30:23

Version Info:

0: [No Data]

Babar.109697 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.AutoProxy.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.109697
McAfeeRDN/Generic Proxy
Cylanceunsafe
VIPREGen:Variant.Babar.109697
SangforTrojan.Win32.Save.a
K7AntiVirusProxy-Program ( 00592b071 )
AlibabaTrojan:Win32/ProxyChanger.ec4f205a
K7GWProxy-Program ( 00592b071 )
Cybereasonmalicious.31b3c6
CyrenW32/ABRisk.JXIE-1617
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/ProxyChanger.XP
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.AutoProxy.gen
BitDefenderGen:Variant.Babar.109697
NANO-AntivirusTrojan.Win32.AutoProxy.juhsqk
AvastWin32:Trojan-gen
TencentWin32.Trojan.Autoproxy.Anhl
EmsisoftGen:Variant.Babar.109697 (B)
F-SecureTrojan.TR/ProxyChange.muyhx
ZillyaTrojan.ProxyChanger.Win32.2729
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.525951731b3c6dfd
SophosMal/Generic-S
IkarusPUA.Generic
GDataGen:Variant.Babar.109697
AviraTR/ProxyChange.muyhx
Antiy-AVLTrojan/Win32.ProxyChanger
ArcabitTrojan.Babar.D1AC81
ZoneAlarmHEUR:Trojan.Win32.AutoProxy.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5347794
BitDefenderThetaAI:Packer.BD0828C21E
ALYacGen:Variant.Babar.109697
MAXmalware (ai score=83)
VBA32suspected of Trojan.Downloader.gen
PandaTrj/Agent.TV
RisingTrojan.Generic@AI.93 (RDML:ZDaTvLw8A8b3t9Ku/rK3Hg)
YandexTrojan.ProxyChanger!eRYHdEWDa44
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.116864476.susgen
FortinetW32/ProxyChanger.XP!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Babar.109697?

Babar.109697 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment