Malware

Babar.255979 removal instruction

Malware Removal

The Babar.255979 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.255979 virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Babar.255979?


File Info:

name: 22193B5BEF48B9E76EE7.mlw
path: /opt/CAPEv2/storage/binaries/5145de7cd9e1735628f5d6e33eaba85d0fa3ee80da6340827122ee7432419e64
crc32: F0B8C4A9
md5: 22193b5bef48b9e76ee7acb9e715257b
sha1: 19713c75cf6fb8ed51f3c69d63e5ecc05d9b68e1
sha256: 5145de7cd9e1735628f5d6e33eaba85d0fa3ee80da6340827122ee7432419e64
sha512: c3830e7bfe092db765dc54dfd064d31e19972ff197a906c9aeccdbbcdd1ded99a42538a259b7550406ba02099c1c7c1501033e73243f332f7591c765374f2c5b
ssdeep: 24576:TACIW5Ytuq1+lTZaqdiXSp0c02uFG6dAk3HMcvvGikNKPHIh8GMG+8pnwfNIjc7I:TVIUgoTZaqdwk0c05HGia5j
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17865F101BBE280F2EE05253045BE677AEE75CA020A26EEC79774ED6D1D73270AD37125
sha3_384: 11ec7bd12d09b4c867aa3896a4cc2c6376ff0000d87f417837cbab7313f080377534fb685b0823237f349cdf501622ef
ep_bytes: 558bec6aff68883b540068cc8c450064
timestamp: 2012-07-13 13:16:40

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: DNF辅助
ProductVersion: 1.0.0.0
CompanyName: 小旭制作
LegalCopyright: 小旭制作 版权所有
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Babar.255979 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Babar.255979
FireEyeGeneric.mg.22193b5bef48b9e7
CAT-QuickHealRisktool.Flystudio.16886
ALYacGen:Variant.Babar.255979
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Babar.255979
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.5cf6fb
BaiduWin32.Rootkit.Agent.f
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/FlyStudio.HackTool.A potentially unwanted
APEXMalicious
ClamAVWin.Malware.Procpatcher-9875517-0
Kasperskynot-a-virus:RiskTool.Win32.ProcPatcher.a
BitDefenderGen:Variant.Babar.255979
AvastWin32:MiscX-gen [PUP]
EmsisoftGen:Variant.Babar.255979 (B)
F-SecureTrojan:W32/DelfInject.R
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.15IBL0F
GoogleDetected
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumWorm.Win32.Dropper.RA@1qraug
ArcabitTrojan.Babar.D3E7EB
ZoneAlarmnot-a-virus:RiskTool.Win32.ProcPatcher.a
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
CynetMalicious (score: 100)
McAfeeGenericRXEM-ZT!22193B5BEF48
VBA32Rootkit.Gen.2
Cylanceunsafe
RisingRootkit.Agent!1.6784 (CLASSIC)
YandexTrojan.GenAsa!JqZpwLvd5bo
IkarusTrojan.Win32.Agent
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.PHP!tr
BitDefenderThetaGen:NN.ZexaF.36738.Er0@ai9AJzfb
AVGWin32:MiscX-gen [PUP]
DeepInstinctMALICIOUS

How to remove Babar.255979?

Babar.255979 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment