Malware

Should I remove “Babar.268239”?

Malware Removal

The Babar.268239 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.268239 virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Babar.268239?


File Info:

name: 0313F05CF59073956583.mlw
path: /opt/CAPEv2/storage/binaries/935319639f43f95ab0543d0bcb183d1a91c8d9b6a23df4d473a94b46a6c2f1eb
crc32: 64E069AC
md5: 0313f05cf59073956583299a0096daa9
sha1: c4d0d9aae1bb12b5f231559a0fc5d42fa40d2a2c
sha256: 935319639f43f95ab0543d0bcb183d1a91c8d9b6a23df4d473a94b46a6c2f1eb
sha512: 8ee40e1ecd052082cb1544dfde9cb1ad46c7c7844b9cfe6dff5b99108a50985622497b6df49949ad8c1e710c7701845357dc358ae5141f07631ae88360632e9b
ssdeep: 12288:uw4pzMGGPv3wZqFv+zorPlqjC+92nBps3SKpZMVBt3KKE0HKruJHnITtHCn7:MpzM/Iqx+EblKC+92nBO5pGKiJHnuti
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14BE423F187EC5EADF08FAC3097A11B4671CDC350E2029D15726A779DEC397462B488BA
sha3_384: 588048b598055acf309ff2dfc95334ebb25769db661ac4c78fc290c30df71d83c07c5a9c4c5166e76ecc2aa5a0bf4e8e
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2010-05-24 04:48:18

Version Info:

0: [No Data]

Babar.268239 also known as:

BkavW32.Common.E04CAADE
LionicTrojan.Win32.Generic.4!c
AVGWin32:Malware-gen
MicroWorld-eScanGen:Variant.Babar.268239
FireEyeGeneric.mg.0313f05cf5907395
CAT-QuickHealRansom.Gimemo.16898
ALYacGen:Variant.Babar.268239
Cylanceunsafe
VIPREGen:Variant.Babar.268239
SangforTrojan.Win32.Dynamer.Vwqo
K7AntiVirusTrojan ( 005246d51 )
K7GWPassword-Stealer ( 004b08171 )
Cybereasonmalicious.ae1bb1
BitDefenderThetaGen:NN.ZexaF.36722.OyWbaKi8N7kb
CyrenW32/S-9642dd0b!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
BitDefenderGen:Variant.Babar.268239
NANO-AntivirusTrojan.Win32.StartPage.cxdmzb
AvastWin32:Malware-gen
SophosGeneric Reputation PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Babar.268239 (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.1NHSFG6
Antiy-AVLTrojan/Win32.Dynamer
XcitiumWorm.Win32.Dropper.RA@1qraug
ArcabitTrojan.Babar.D417CF
MicrosoftTrojan:Win32/Dynamer!ac
GoogleDetected
VBA32BScope.Trojan.Valcaryx
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R002H0CE123
RisingTrojan.Dynamer!8.3A0 (CLOUD)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.ELG!tr.pws
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Babar.268239?

Babar.268239 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment