Malware

What is “Babar.27125”?

Malware Removal

The Babar.27125 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.27125 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Babar.27125?


File Info:

crc32: 000BFC68
md5: c34157e025416d3ddf0a8610fa2e8b98
name: C34157E025416D3DDF0A8610FA2E8B98.mlw
sha1: 03005c0c1469b7dbe9eff095bfd3ecbc3a713811
sha256: f285822ef8c947a87e556858a8332ed26edda052e597c67a7831753c376e01b4
sha512: 16de23d61d7dad4f239980ac02aa765be38bc42647c63ede13441a73c002bd0b91a4681159cca9170f41fa003a7725926b61c09a124fec700028de7c425679cd
ssdeep: 12288:F3QbugX6FgNAgKHDDn6KGxQLfgdVUUyAHE:dJfmNlKHiKGM4dVUUG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0407 0x04b0
ProductVersion: 1.00
InternalName: ec2ndm4seaw7dmc
FileVersion: 1.00
OriginalFilename: ec2ndm4seaw7dmc.exe
ProductName: Cesarumenuvcer

Babar.27125 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Babar.27125
CylanceUnsafe
Cybereasonmalicious.c1469b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EPMB
APEXMalicious
AvastWin32:RATX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Chapak.vho
BitDefenderGen:Variant.Babar.27125
MicroWorld-eScanGen:Variant.Babar.27125
Ad-AwareGen:Variant.Babar.27125
BitDefenderThetaGen:NN.ZevbaF.34722.Gm2@a0!OXvE
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.c34157e025416d3d
EmsisoftGen:Variant.Babar.27125 (B)
SentinelOneStatic AI – Suspicious PE
eGambitPE.Heur.InvalidSig
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Babar.D69F5
ZoneAlarmHEUR:Trojan.Win32.Chapak.vho
GDataGen:Variant.Babar.27125
Acronissuspicious
McAfeeRDN/Generic.hbg
MAXmalware (ai score=86)
VBA32Trojan.Chapak
MalwarebytesTrojan.VBCrypt
PandaTrj/GdSda.A
RisingMalware.Heuristic!ET#93% (RDMK:cmRtazoIM8Jda9ZgLb4cAp/q8Gj5)
IkarusTrojan.Win32.VBKrypt
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml

How to remove Babar.27125?

Babar.27125 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment