Malware

About “Babar.117537” infection

Malware Removal

The Babar.117537 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.117537 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Creates a copy of itself
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Babar.117537?


File Info:

name: 1BAE482F7E4DD549499C.mlw
path: /opt/CAPEv2/storage/binaries/df3f15fcfe64552fde3c2ab888742415a7a1d7d23cfa342ec50a54ea101df494
crc32: B7E57EEC
md5: 1bae482f7e4dd549499c1cf4fb4a7141
sha1: 14e8576ab5d1276c406d2a4c15c26377eb65b57e
sha256: df3f15fcfe64552fde3c2ab888742415a7a1d7d23cfa342ec50a54ea101df494
sha512: 405e3de1090a6d5a60b53966bb33fc6a551750c37bb7be44dceb8556177fb6a2994e0ab7a047491def9562b2804594574a30991c33470ede3165c2b5d3afa61e
ssdeep: 1536:cEBguwGA51GPzhvI6VQv1dHk0KGgerrVSkE5zMrXk6Ntt9iZ0Iu1PID8FhcQNh5t:c+gn5KzuzdjKGBrEF5KVAB+QoDxE0aH8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T119D31232BCAA8CF2C0BAA3783731A3A2715AB7855ADC45797AC05535EDD049CDB4378C
sha3_384: 3e856eac50e7b87bf4187d200bd326cd97ce03126d43a0a40622b4d2378bdd9740458f7ea3b8e5b8423fcdf7238dba27
ep_bytes: 60be009041008dbe0080feff5783cdff
timestamp: 2002-02-15 16:25:16

Version Info:

CompanyName: Chit Typo
FileDescription: Cheat Bums Abacus
FileVersion: 81.13.10.16
InternalName: Lowry
LegalCopyright: Copyright © Funky Greek 2001-2007
OriginalFilename: Gusto.exe
ProductName: Weedy
ProductVersion: 81.13.10.16
Translation: 0x0409 0x04b0

Babar.117537 also known as:

LionicTrojan.Win32.Generic.ledB
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Babar.117537
ClamAVWin.Worm.Autorunvb-7053731-0
McAfeeGenericRXAA-AA!1BAE482F7E4D
MalwarebytesVirut.Virus.FileInfector.DDS
VIPREGen:Variant.Babar.117537
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Starter.ali2000005
VirITTrojan.Win32.Generic.UEV
CyrenW32/Trojan.RLJZ-4741
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Bflient.Y
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Babar.117537
NANO-AntivirusTrojan.Win32.Drop.donrpg
AvastWin32:Crypt-KOW [Trj]
TencentMalware.Win32.Gencirc.115dfc13
EmsisoftGen:Variant.Babar.117537 (B)
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebTrojan.MulDrop2.34471
ZillyaWorm.FFAuto.Win32.26
TrendMicroTROJ_RIMECUD_BK082E6E.TOMC
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.1bae482f7e4dd549
SophosMal/Generic-R
IkarusVirus.Win32.Virut
GDataGen:Variant.Babar.117537
JiangminTrojan/Generic.tdkw
AviraTR/Crypt.ULPM.Gen
Antiy-AVLWorm/Win32.FFAuto
XcitiumTrojWare.Win32.Bflient.KWC@4xogjk
ArcabitTrojan.Babar.D1CB21
ViRobotWorm.Win32.A.FFAuto.113152
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Rimecud.A
GoogleDetected
AhnLab-V3Spyware/Win32.Zbot.C61722
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36132.im0@aOlH5Dbi
ALYacGen:Variant.Babar.117537
MAXmalware (ai score=81)
VBA32Trojan.LE.01359
Cylanceunsafe
PandaBck/Qbot.AO
ZonerTrojan.Win32.3107
TrendMicro-HouseCallTROJ_RIMECUD_BK082E6E.TOMC
RisingTrojan.Rimecud!8.60A (CLOUD)
YandexTrojan.Agent!UHl6/GmLmGE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bredo.A!tr
AVGWin32:Crypt-KOW [Trj]
DeepInstinctMALICIOUS

How to remove Babar.117537?

Babar.117537 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment