Categories: Malware

Babar.17768 (file analysis)

The Babar.17768 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.17768 virus can do?

  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Babar.17768?


File Info:

name: 20AACF1ABCDC18D41492.mlwpath: /opt/CAPEv2/storage/binaries/58665d643de6ec68f938c057b8996ba576a22d553ed39d5ab8fa9752c57e0470crc32: 3D713AC2md5: 20aacf1abcdc18d4149215942ca7080dsha1: 85a5c6ba07c4414d021516b50da8057981def613sha256: 58665d643de6ec68f938c057b8996ba576a22d553ed39d5ab8fa9752c57e0470sha512: 7bf2a5ab1cbb65b662f89f9a4620d5d92971feab5f1e13c1383dae5e3d10a5f2c8ca35a8e9845109047918fe77879151406bbb34002a0c4b5b687ef614e02290ssdeep: 12288:1qd41YtluKAPzg5ec2HpYtSIbdguRcFoxQ+pKIxjTLJQs6:1qW1AuKE8ec2HpYkdbSQOlnN6type: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T1F2B423555794841BE1E3867A861265DFEF75EC2B10ACBA4B0358788038B3B71FA1E363sha3_384: 0c6126126500d120ad8d38b39d41e9db10f838fd2e31ac580bdd18bd21e75af353a9c19e48417f45b4aee7106c8fbd3fep_bytes: 81ecd40200005356576a205f33db6801timestamp: 2018-12-15 22:24:46

Version Info:

0: [No Data]

Babar.17768 also known as:

Bkav W32.AIDetect.malware1
Lionic Trojan.Win32.Coinminer.4!e
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Babar.17768
FireEye Generic.mg.20aacf1abcdc18d4
ALYac Gen:Variant.Babar.17768
Cylance Unsafe
Sangfor Trojan.Win32.DefenseEvasion.rfn
K7AntiVirus Trojan ( 005543211 )
Alibaba Trojan:Win32/DefenseEvasion.cbb147ee
K7GW Trojan ( 005543211 )
Cybereason malicious.abcdc1
Cyren W32/Injector.BUZO-0668
Symantec Trojan.Gen.2
ESET-NOD32 Win32/Injector.EGXR
APEX Malicious
Paloalto generic.ml
ClamAV Win.Trojan.Generic-7489028-0
Kaspersky HEUR:Trojan.Win32.Agent.gen
BitDefender Gen:Variant.Babar.17768
NANO-Antivirus Trojan.Win32.TrjGen.fvufkr
Avast Win32:Trojan-gen
Tencent Win32.Trojan.Agent.Hpsc
Ad-Aware Gen:Variant.Babar.17768
Sophos Mal/Generic-S + Troj/Agent-BCEZ
Comodo Malware@#2z69zafbxy3v9
DrWeb Trojan.Siggen8.39992
TrendMicro TrojanSpy.Win32.NEGASTEAL.DYSHAA
McAfee-GW-Edition BehavesLike.Win32.Vopak.hc
Emsisoft Gen:Variant.Babar.17768 (B)
GData Gen:Variant.Babar.17768
Webroot W32.Trojan.Gen
Avira HEUR/AGEN.1117990
Antiy-AVL Trojan/Generic.ASSuf.2E0F6
Arcabit Trojan.Babar.D4568
Microsoft Trojan:Win32/Occamy.C58
Cynet Malicious (score: 99)
McAfee Artemis!20AACF1ABCDC
VBA32 Trojan.Agent
Malwarebytes Trojan.Injector
TrendMicro-HouseCall TrojanSpy.Win32.NEGASTEAL.DYSHAA
Rising Trojan.Generic@ML.80 (RDML:qQE6LnvX7lp4IPM2ERo4UA)
Yandex Trojan.Injector!sSV3gGEThgs
Fortinet W32/Injector.EHVV!tr
BitDefenderTheta AI:Packer.DB46B72721
AVG Win32:Trojan-gen
Panda Trj/CI.A
CrowdStrike win/malicious_confidence_100% (W)

How to remove Babar.17768?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

MSIL/GenKryptik.GXIZ information

The MSIL/GenKryptik.GXIZ is considered dangerous by lots of security experts. When this infection is active,…

1 month ago

Malware.AI.2789448175 (file analysis)

The Malware.AI.2789448175 is considered dangerous by lots of security experts. When this infection is active,…

1 month ago

Jalapeno.1878 removal instruction

The Jalapeno.1878 is considered dangerous by lots of security experts. When this infection is active,…

1 month ago

What is “Trojan.Heur3.LPT.YmKfaKBcBekib”?

The Trojan.Heur3.LPT.YmKfaKBcBekib is considered dangerous by lots of security experts. When this infection is active,…

1 month ago

How to remove “Worm.Win32.Vobfus.exmt”?

The Worm.Win32.Vobfus.exmt is considered dangerous by lots of security experts. When this infection is active,…

1 month ago

About “TrojanDownloader:Win32/Beebone.JO” infection

The TrojanDownloader:Win32/Beebone.JO is considered dangerous by lots of security experts. When this infection is active,…

1 month ago