Malware

Babar.13965 removal

Malware Removal

The Babar.13965 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.13965 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Babar.13965?


File Info:

crc32: 590661C1
md5: 98be0fa3f856cf64549b3831df5a5d5b
name: 98BE0FA3F856CF64549B3831DF5A5D5B.mlw
sha1: db6f9175142525fd7fbf88bfcca734634edb45f9
sha256: 00047c12e441034d25e3e535303ec00af88b77d840f7b4a9c7ead28e231b9e98
sha512: d885d7f7fbec84f14f9114f2b602e75ff061c5256d8abfbc2b63b43b512f8bd4486dda780951fad015df6854a42f58e9266b25138bc939613e79d23610666a7c
ssdeep: 49152:fqrUvedDX/eLz1rupwHWXtMqpirJ0V3WpqTrCq9YFUxDHCaV0:CrH9X/USrMqpRlLMqT0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 FxSound
FileVersion: 13.025.0.0
CompanyName: FxSound
Comments:
ProductName: FxSound Enhancer v13.025
FileDescription: FxSound Enhancer v13.025
Translation: 0x0000 0x04b0

Babar.13965 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00540e101 )
LionicTrojan.Win32.Generic.4!c
CynetMalicious (score: 99)
ALYacGen:Variant.Babar.13965
CylanceUnsafe
ZillyaTrojan.Fsysna.Win32.16531
AlibabaTrojan:Win32/Fsysna.09de37c8
K7GWTrojan ( 00540e101 )
Cybereasonmalicious.3f856c
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EBNY
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.Fsysna.eyho
BitDefenderGen:Variant.Babar.13965
MicroWorld-eScanGen:Variant.Babar.13965
TencentMalware.Win32.Gencirc.114d54ca
Ad-AwareGen:Variant.Babar.13965
SophosMal/Generic-S
ComodoApplicUnwnt@#1c7reztq5839f
BitDefenderThetaAI:Packer.CEEC508D20
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.vc
FireEyeGeneric.mg.98be0fa3f856cf64
EmsisoftGen:Variant.Babar.13965 (B)
SentinelOneStatic AI – Suspicious PE
AviraADWARE/HiRu.tstew
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan.Win32.Fsysna.eyho
GDataGen:Variant.Babar.13965
McAfeeArtemis!98BE0FA3F856
MAXmalware (ai score=80)
VBA32BScope.Trojan.Buzus
PandaTrj/CI.A
YandexTrojan.Fsysna!+gsgCIC8R9A
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.112053558.susgen
FortinetW32/Generic.AC.42D71F
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Babar.13965?

Babar.13965 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment