Malware

Should I remove “Babar.135889”?

Malware Removal

The Babar.135889 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.135889 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Babar.135889?


File Info:

name: E855125667299E91FAE3.mlw
path: /opt/CAPEv2/storage/binaries/2d51ecd794cccb6a2ffd48b2e157ac748b1a2f4e9ae22a72740fbbdba048e5e2
crc32: D9A1F969
md5: e855125667299e91fae327ca4b7bd4ce
sha1: 88d838dad08789fc3f21dba9e1944b3f0741829c
sha256: 2d51ecd794cccb6a2ffd48b2e157ac748b1a2f4e9ae22a72740fbbdba048e5e2
sha512: e77d0897ab6d49616160b7885a1a5951d8549daef523a41e3b325949a45241de613d53e44eff0b2f3a712992e4b141192c5c718ab0aee93891f9667fdcd6920c
ssdeep: 196608:37WQtdt9FIn7MHs7KWsn7MHs7aE20yaaMc/ic/K0hs+c/6c/2:3pPIms7Fsms7p2iad/P/fI/X/2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14AC6BF137821D851E8800B3FD5D2863824662F54A8B6C857F76CBE67BF786135A2F70B
sha3_384: 6447555d32839a08a19007a3c34701c25db87861b1c2f3561d7565578af642b5d6f804020b6872d7c095dd87cdbb5e43
ep_bytes: 558bec6aff688801f50068046c770064
timestamp: 2016-12-21 16:33:36

Version Info:

FileVersion: 3.1.2.0
FileDescription: 麦霸VIP影院
ProductName: 麦霸VIP影院
ProductVersion: 3.1.2.0
CompanyName: 麦霸传说
LegalCopyright: 麦霸VIP影院 @版权归麦霸传说所有
Comments: 麦霸VIP影院
Translation: 0x0804 0x04b0

Babar.135889 also known as:

tehtrisGeneric.Malware
FireEyeGeneric.mg.e855125667299e91
ALYacGen:Variant.Babar.135889
Cylanceunsafe
SangforTrojan.Win32.Agent.Vsxn
K7AntiVirusAdware ( 0050718d1 )
K7GWAdware ( 0050718d1 )
CrowdStrikewin/malicious_confidence_60% (D)
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Babar.135889
MicroWorld-eScanGen:Variant.Babar.135889
AvastWin32:Malware-gen
EmsisoftGen:Variant.Babar.135889 (B)
VIPREGen:Variant.Babar.135889
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SophosGeneric Reputation PUA (PUA)
IkarusTrojan.Adduser
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
ArcabitTrojan.Babar.D212D1
GDataWin32.Trojan.PSE.10248TU
GoogleDetected
Acronissuspicious
McAfeeArtemis!E85512566729
MAXmalware (ai score=85)
VBA32BScope.Trojan.Tiggre
MalwarebytesMalware.AI.3427822939
TrendMicro-HouseCallTROJ_GEN.R002H09LV22
RisingTrojan.Generic@AI.100 (RDML:PK3cX4eQZnZahfbbTs12HQ)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.PHP!tr
BitDefenderThetaGen:NN.ZexaF.36196.@t0@aespznfb
AVGWin32:Malware-gen
Cybereasonmalicious.ad0878
DeepInstinctMALICIOUS

How to remove Babar.135889?

Babar.135889 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment