Malware

Babar.23468 malicious file

Malware Removal

The Babar.23468 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.23468 virus can do?

  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Babar.23468?


File Info:

name: BD5DFEBF5A30E9BC77AC.mlw
path: /opt/CAPEv2/storage/binaries/e24b6e2d8a7262e354144dd0630404f1df28a4003c1a1319f4847be2c22c4201
crc32: 0B891CA7
md5: bd5dfebf5a30e9bc77ac7e1d7015b6b9
sha1: 4a7814e65d107bd7ace46d3ec8c72afdf640fac3
sha256: e24b6e2d8a7262e354144dd0630404f1df28a4003c1a1319f4847be2c22c4201
sha512: a19005c5afc8c84d405fba191feb06e5c7d11dc5a2ffa21149d15b88f4bc4d6073d975a5924bd69d35c14a59d26eefa5ed594aab6118a6ac76c574c0ad52b5d4
ssdeep: 6144:BPBmYdzwEs09ZfVZcYRHOUoSDSQJkiqpcq22Lb+D:9fBwkffzcY4UTlOiN1Q+D
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14D34021AA5F4DDDFD04A47300A717369D235C2DF20BB1407A768BF69AA33082CD99B96
sha3_384: 785cc8f8ac0011b305f7f55c4d9f3d4e38099255f02b6b4edcc188529f7d44e164de3aa914b41b7b4fcf59a3bcd1ca8f
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:58

Version Info:

0: [No Data]

Babar.23468 also known as:

BkavW32.FamVT.GluptebaBTTc.Worm
Elasticmalicious (high confidence)
DrWebTrojan.Siggen13.36816
MicroWorld-eScanGen:Variant.Babar.23468
FireEyeGeneric.mg.bd5dfebf5a30e9bc
ALYacGen:Variant.Babar.23468
CylanceUnsafe
Cybereasonmalicious.f5a30e
CyrenW32/Ninjector.A!Camelot
SymantecPacked.Generic.610
ESET-NOD32a variant of Win32/GenKryptik.EUMG
KasperskyHEUR:Backdoor.Win32.Remcos.gen
BitDefenderGen:Variant.Babar.23468
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Babar.23468
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
EmsisoftGen:Variant.Babar.23468 (B)
IkarusTrojan.Win32.Injector
GDataGen:Variant.Babar.23468
MaxSecureTrojan.Malware.121218.susgen
AviraTR/Crypt.XPACK.Gen
ArcabitTrojan.Babar.D5BAC
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
VBA32BScope.Adware.ShouQu
MalwarebytesSpyware.FormBook.NSIS
APEXMalicious
RisingTrojan.Injector/NSIS!1.D63B (CLASSIC)
MAXmalware (ai score=84)
FortinetW32/CoinMiner.3E08!tr
AVGWin32:Malware-gen

How to remove Babar.23468?

Babar.23468 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment