Malware

Babar.138161 removal

Malware Removal

The Babar.138161 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.138161 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Babar.138161?


File Info:

name: CA4224A51ED47F4323B3.mlw
path: /opt/CAPEv2/storage/binaries/b5b621ac01ef50c6d09def0b7a7ce88890bec5c8c2039a6abdf2b4fcd7de9496
crc32: 0E2D49F8
md5: ca4224a51ed47f4323b3730b53850a1c
sha1: cf71f72b4b4b24ceac672e84caeca512b031f1ab
sha256: b5b621ac01ef50c6d09def0b7a7ce88890bec5c8c2039a6abdf2b4fcd7de9496
sha512: 1ec79137103b2d20d76e547585a171cf7eba856ce5d8a3ef98331b1b8b9b99373fa05b6d9672a16d8298bc012716d9cbe700bf7a792adb9705d18562361335fa
ssdeep: 12288:15LXlb3wv9I5T93f+mq//3yhd+qKffH7qfsQtMTJgaEuEcp+aJ:Xlmy5T9P+mq/RqKf2fztEJSYp/
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1C605233474816963FB670875CAD8C68FF890C9B3BC2467C7552CF8D299DAD8D0A148BE
sha3_384: 34f0b2a06e5bfdf5a9cec71aaf711b8f131f547db3192e50036277103fcc077c10ea113eaa31a5ddbbf5feaff4fff413
ep_bytes: ba0000000083ec04893c2441515e01f6
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Babar.138161 also known as:

BkavW32.AIDetectMalware
LionicRiskware.Win32.BitCoinMiner.1!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Babar.138161
FireEyeGeneric.mg.ca4224a51ed47f43
SkyhighBehavesLike.Win32.Generic.bc
ALYacGen:Variant.Babar.138161
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
AlibabaTrojan:Win32/BitCoinMiner.1e36f238
K7GWTrojan ( 005762bf1 )
Cybereasonmalicious.b4b4b2
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HITO
CynetMalicious (score: 100)
APEXMalicious
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
BitDefenderGen:Variant.Babar.138161
NANO-AntivirusRiskware.Win32.BitCoinMiner.iisijf
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
EmsisoftGen:Variant.Babar.138161 (B)
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebTrojan.Packed2.43250
VIPREGen:Variant.Babar.138161
SophosMal/HckPk-A
IkarusTrojan.Win32.Injector
JiangminRiskTool.BitCoinMiner.umr
VaristW32/CoinMiner.CQ.gen!Eldorado
AviraTR/Crypt.ULPM.Gen
Antiy-AVLGrayWare/Win32.Kryptik.ffp
MicrosoftTrojan:Win32/Injector.RAQ!MTB
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Babar.D21BB1
ZoneAlarmnot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
GDataGen:Variant.Babar.138161
GoogleDetected
AhnLab-V3Malware/Win32.Generic.R369407
McAfeeGenericRXAA-AA!CA4224A51ED4
MAXmalware (ai score=81)
VBA32Trojan.Packed
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.D238 (CLASSIC)
YandexTrojan.Kryptik!2K/AEsMsnNY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.74654884.susgen
FortinetW32/Kryptik.EAHK!tr
BitDefenderThetaGen:NN.ZexaF.36792.XmW@a4u6LMo
AVGWin32:CoinminerX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Babar.138161?

Babar.138161 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment