Malware

Babar.24623 removal

Malware Removal

The Babar.24623 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.24623 virus can do?

  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Ukrainian
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Babar.24623?


File Info:

crc32: 1F222EA6
md5: 0381e3aa7f107054677b2e904be98f08
name: 0381E3AA7F107054677B2E904BE98F08.mlw
sha1: 1fbed995fbb4547c84f330c7d256cea0579137ce
sha256: d0571be232325e0c531027aa9ebc7c09719540bc00e651f09eff0bd096849652
sha512: f10b2d21c84c25f0756733266f5c7be9a51b8e58b1c05c5461a4043818cd5fd081aa0ba0cf6b700b2d08315f7bd6885c4c76d0d90b680c760001de18589ba562
ssdeep: 384:k1j6ok13CUILQ+uA7OERpT7hopwzwZD+TEHe4atGa+VS0sJWN0BPfxkuj:kB/r7hop+oD+SatGtVJYm0TF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2012
InternalName: exe
FileVersion: 1, 0, 0, 1
ProductName: exe
ProductVersion: 1, 0, 0, 1
FileDescription: exe
OriginalFilename: exe
Translation: 0x0419 0x04b0

Babar.24623 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e4091 )
LionicTrojan.Win32.PornoAsset.j!c
DrWebTrojan.Winlock.7443
CynetMalicious (score: 99)
ALYacGen:Variant.Babar.24623
CylanceUnsafe
ZillyaTrojan.PornoAsset.Win32.14721
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 0055e4091 )
Cybereasonmalicious.a7f107
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/LockScreen.AOU
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.ljly
BitDefenderGen:Variant.Babar.24623
NANO-AntivirusTrojan.Win32.PornoAsset.csatrs
MicroWorld-eScanGen:Variant.Babar.24623
TencentWin32.Trojan.Pornoasset.Eej
Ad-AwareGen:Variant.Babar.24623
SophosML/PE-A
ComodoMalware@#c39w7yp6kqb6
BitDefenderThetaAI:Packer.A2C4AE9D1F
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.0381e3aa7f107054
EmsisoftGen:Variant.Babar.24623 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1114183
Antiy-AVLTrojan/Generic.ASMalwS.12C0F5
KingsoftWin32.Troj.Undef.(kcloud)
GDataGen:Variant.Babar.24623
AhnLab-V3Trojan/Win32.PornoAsset.R81573
McAfeeArtemis!0381E3AA7F10
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Tobfy
RisingTrojan.Generic@ML.92 (RDML:Ghs1fMTWSt3YGP+YlMci/Q)
YandexTrojan.GenAsa!Fw34Y825NfA
IkarusTrojan.Win32.Tobfy
MaxSecureTrojan.Malware.5536140.susgen
FortinetW32/PornoAsset.AOU!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Babar.24623?

Babar.24623 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment