Malware

Babar.17768 (file analysis)

Malware Removal

The Babar.17768 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.17768 virus can do?

  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Babar.17768?


File Info:

name: 20AACF1ABCDC18D41492.mlw
path: /opt/CAPEv2/storage/binaries/58665d643de6ec68f938c057b8996ba576a22d553ed39d5ab8fa9752c57e0470
crc32: 3D713AC2
md5: 20aacf1abcdc18d4149215942ca7080d
sha1: 85a5c6ba07c4414d021516b50da8057981def613
sha256: 58665d643de6ec68f938c057b8996ba576a22d553ed39d5ab8fa9752c57e0470
sha512: 7bf2a5ab1cbb65b662f89f9a4620d5d92971feab5f1e13c1383dae5e3d10a5f2c8ca35a8e9845109047918fe77879151406bbb34002a0c4b5b687ef614e02290
ssdeep: 12288:1qd41YtluKAPzg5ec2HpYtSIbdguRcFoxQ+pKIxjTLJQs6:1qW1AuKE8ec2HpYkdbSQOlnN6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F2B423555794841BE1E3867A861265DFEF75EC2B10ACBA4B0358788038B3B71FA1E363
sha3_384: 0c6126126500d120ad8d38b39d41e9db10f838fd2e31ac580bdd18bd21e75af353a9c19e48417f45b4aee7106c8fbd3f
ep_bytes: 81ecd40200005356576a205f33db6801
timestamp: 2018-12-15 22:24:46

Version Info:

0: [No Data]

Babar.17768 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Coinminer.4!e
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.17768
FireEyeGeneric.mg.20aacf1abcdc18d4
ALYacGen:Variant.Babar.17768
CylanceUnsafe
SangforTrojan.Win32.DefenseEvasion.rfn
K7AntiVirusTrojan ( 005543211 )
AlibabaTrojan:Win32/DefenseEvasion.cbb147ee
K7GWTrojan ( 005543211 )
Cybereasonmalicious.abcdc1
CyrenW32/Injector.BUZO-0668
SymantecTrojan.Gen.2
ESET-NOD32Win32/Injector.EGXR
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-7489028-0
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderGen:Variant.Babar.17768
NANO-AntivirusTrojan.Win32.TrjGen.fvufkr
AvastWin32:Trojan-gen
TencentWin32.Trojan.Agent.Hpsc
Ad-AwareGen:Variant.Babar.17768
SophosMal/Generic-S + Troj/Agent-BCEZ
ComodoMalware@#2z69zafbxy3v9
DrWebTrojan.Siggen8.39992
TrendMicroTrojanSpy.Win32.NEGASTEAL.DYSHAA
McAfee-GW-EditionBehavesLike.Win32.Vopak.hc
EmsisoftGen:Variant.Babar.17768 (B)
GDataGen:Variant.Babar.17768
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1117990
Antiy-AVLTrojan/Generic.ASSuf.2E0F6
ArcabitTrojan.Babar.D4568
MicrosoftTrojan:Win32/Occamy.C58
CynetMalicious (score: 99)
McAfeeArtemis!20AACF1ABCDC
VBA32Trojan.Agent
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTrojanSpy.Win32.NEGASTEAL.DYSHAA
RisingTrojan.Generic@ML.80 (RDML:qQE6LnvX7lp4IPM2ERo4UA)
YandexTrojan.Injector!sSV3gGEThgs
FortinetW32/Injector.EHVV!tr
BitDefenderThetaAI:Packer.DB46B72721
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Babar.17768?

Babar.17768 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment