Malware

Babar.185300 removal

Malware Removal

The Babar.185300 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.185300 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Babar.185300?


File Info:

name: 57122D543E663AE77CC2.mlw
path: /opt/CAPEv2/storage/binaries/3298a3634fd443961956bed0330d0d651cfd7b13e4bea71e35d5096d11d4d450
crc32: 4C488D11
md5: 57122d543e663ae77cc28d9e0b2d0ced
sha1: cb8cab27b3bc7bfd62c8a30e5e22cd11aafa0a7d
sha256: 3298a3634fd443961956bed0330d0d651cfd7b13e4bea71e35d5096d11d4d450
sha512: 6b060220a21ede2fbb93b79e9d976fca5d98ad5e636b8c41789b5cd56621f1a28af6486470739c8e2864734597014961c8d9586911c4b98688e83018b4f0e0f1
ssdeep: 24576:zwBoHc5967qKvDvRO56n4J8fqBj3EICH:zf+KvDvRO598fIjLCH
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1350523FC2982153FF2F9533B61D3CDB2208E360AE71349A16604FC94588B5AE9F16F95
sha3_384: 378394dbbeb5c53df030c6cd9ca5c9a9dcb70b58c4a033aa6427ed65abac43222b1b59fa6dc6b120de51a084c1c9f9a9
ep_bytes: 68000000005f52be6680fbcc09f35909
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Babar.185300 also known as:

BkavW32.AIDetectMalware
LionicRiskware.Win32.BitCoinMiner.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.185300
FireEyeGeneric.mg.57122d543e663ae7
McAfeeGenericRXAA-FA!57122D543E66
MalwarebytesTrojan.MalPack.UPX
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057ffc71 )
AlibabaMalware:Win32/km_280b22.None
K7GWTrojan ( 005762bf1 )
Cybereasonmalicious.7b3bc7
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
BitDefenderGen:Variant.Babar.185300
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
SophosMal/HckPk-A
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebTrojan.Packed2.43250
VIPREGen:Variant.Babar.185300
TrendMicroTROJ_GEN.R002C0DGU23
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
EmsisoftGen:Variant.Babar.185300 (B)
IkarusTrojan.Win32.Injector
GDataGen:Variant.Babar.185300
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=82)
Antiy-AVLGrayWare/Win32.Kryptik.ffp
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Babar.D2D3D4
ZoneAlarmnot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
MicrosoftTrojan:Win32/Injector.RAQ!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Reputation.R436725
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36318.XmW@aGBbtPh
ALYacGen:Variant.Babar.185300
VBA32Trojan.Packed
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DGU23
RisingTrojan.Injector!1.C865 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Babar.185300?

Babar.185300 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment