Malware

Babar.129821 information

Malware Removal

The Babar.129821 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.129821 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Babar.129821?


File Info:

name: 436FE91B7384C346AFE8.mlw
path: /opt/CAPEv2/storage/binaries/ebfe5770c29270ddba5903da31761b4adc99b20e5e1a20013829274833b9f299
crc32: 28977849
md5: 436fe91b7384c346afe823945e62caf1
sha1: e1fc02545cc9509df831f5679d4efae245a94ca3
sha256: ebfe5770c29270ddba5903da31761b4adc99b20e5e1a20013829274833b9f299
sha512: 7f61b4b366b72cbccb190c15930cdeb2c23eed24c8f0e4a9244b36b6730e8b410f81d3e0665e537713d52a36e74da10378010923680bcf4fa68d16d5df93da34
ssdeep: 24576:XsT5Hnwz3XCHyUjrZvjrbvK9rsrHV3h/jQsnLufnDAvdzzP/oBmG8uqlSoH76gu/:XOHEAf5lj6gupxpvME+q3kukYb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B3953A13E042C062E90505B03AB6A7397D7967755D32C683FBE8DEF9BF62131876620E
sha3_384: 02bd755b2b6e6e106d6a289d38b376117f09289f8b7886a5a9ec73fa7310d3991ae881f0b5c7aaa13de1540f71269a72
ep_bytes: 558bec6aff6898a55c0068a454550064
timestamp: 2023-04-16 13:21:05

Version Info:

FileVersion: 1.0.0.0
FileDescription: Windows
ProductName: 暗夜奇迹登录器
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: Windows
Translation: 0x0804 0x04b0

Babar.129821 also known as:

AVGWin32:TrojanX-gen [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.129821
CAT-QuickHealHacktool.Flystudio.16558
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.b7384c
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Generic-9916974-0
Kasperskynot-a-virus:AdWare.Win32.HiddenInstall.tj
BitDefenderGen:Variant.Babar.129821
AvastWin32:TrojanX-gen [Trj]
SophosGeneric ML PUA (PUA)
VIPREGen:Variant.Babar.129821
McAfee-GW-EditionBehavesLike.Win32.Generic.th
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.436fe91b7384c346
EmsisoftGen:Variant.Babar.129821 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.15MOKEC
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
ArcabitTrojan.Babar.D1FB1D
ZoneAlarmnot-a-virus:AdWare.Win32.HiddenInstall.tj
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Gen
BitDefenderThetaGen:NN.ZexaF.36164.9r0@aOt!1ijb
ALYacGen:Variant.Babar.129821
MalwarebytesFlyStudio.Trojan.MalPack.DDS
RisingDropper.Daws!8.3FB (TFE:5:RBTaZXzETSU)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.ELG!tr.pws
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Babar.129821?

Babar.129821 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment