Malware

Babar.22766 removal

Malware Removal

The Babar.22766 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.22766 virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:27783
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Attempts to execute a powershell command with suspicious parameter/s
  • Collects information about installed applications
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

How to determine Babar.22766?


File Info:

crc32: 3F6C3F67
md5: 270b0d717a26f29d23245f39fdeb51c4
name: asura.exe
sha1: 1e2637a488f47243f2d2945de69c237da80447ae
sha256: 05262df9d4366d94157c470c4227c63472aa3c3ee7a9978dfa69e0db46e3ca8c
sha512: 15f0b4d2a5c37ec4fb3fd1e6153ac1583e7a3041410a79bc478591e1074448c8a45c8496ed315a7293aa61650475e3bd6f18699c97bab2de187be66874bc4227
ssdeep: 98304:W53BzDgtva+VYS3D20kpeiscQmw6H/G/hFEMbHgJDRP+HRX7:W9BfgtjZkpXs1mFfYhFvLgJdP+d7
type: PE32 executable (GUI) Intel 80386 system file, for MS Windows

Version Info:

InternalName: wriheovbz.ote
FileVers: 1.2.58
Copyright: Copyrighd (C) 2020, pumke
TranslationUsi: 0x0431 0x0cca

Babar.22766 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
McAfeeArtemis!270B0D717A26
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Babar.22766
K7GWTrojan ( 00571e0a1 )
InvinceaGeneric ML PUA (PUA)
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/GenKryptik.80739eb4
MicroWorld-eScanGen:Variant.Babar.22766
Ad-AwareGen:Variant.Babar.22766
EmsisoftGen:Variant.Babar.22766 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
FireEyeGeneric.mg.270b0d717a26f29d
SentinelOneDFI – Suspicious PE
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Azorult.FW!MTB
GDataWin32.Trojan-Stealer.Petef.UXBI7N
Acronissuspicious
MalwarebytesTrojan.MalPack
ESET-NOD32a variant of Win32/GenKryptik.EVER
RisingTrojan.Generic@ML.100 (RDML:WSdVtybKwBUl5Z162IW5dw)
IkarusTrojan.Win32.Glupteba
eGambitUnsafe.AI_Score_98%
FortinetMalicious_Behavior.SB
BitDefenderThetaGen:NN.ZexaF.34590.@t1@aaQZs4be
Cybereasonmalicious.488f47
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM10.2.E0FA.Malware.Gen

How to remove Babar.22766?

Babar.22766 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment