Malware

Should I remove “Babar.27529”?

Malware Removal

The Babar.27529 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.27529 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The sample enumerated directory objects, possibly probing for Virtual Machine objects.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Deletes its original binary from disk
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
8awang.com
tiebapic.baidu.com
41ku.cn

How to determine Babar.27529?


File Info:

crc32: 0AC4FC17
md5: acae61c2bd42dcecbd206f7c4c73de2c
name: ACAE61C2BD42DCECBD206F7C4C73DE2C.mlw
sha1: ce5366839ca1171746cd92181df84e932d127483
sha256: 51754c3290e03e5c9a6f0c018c12a2c374127244c70b2d2e1472adafc867dcb3
sha512: c33cd465905745a06c381e3c1efdbdf2f46c1296d3865c19a225e34b8ca1829be9fdad2aee1991742ee699e8c54cfd6d94cb783ae0e569d92bf59ed0fc7762c8
ssdeep: 3072:OtRcqHouTOPoHP6Vz9leZH9qthovXmWgX+dPNcxQ1yqgsYAwSoutn+:OtRxHJP6dEehYXmWfdv+AdoS+
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Babar.27529 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.27529
ALYacGen:Variant.Babar.27529
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
Cybereasonmalicious.2bd42d
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Agent.vho
BitDefenderGen:Variant.Babar.27529
TencentWin32.Trojan.Agent.Lpvi
Ad-AwareGen:Variant.Babar.27529
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1133398
BitDefenderThetaAI:Packer.36FBEDE81F
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.acae61c2bd42dcec
EmsisoftGen:Variant.Babar.27529 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1133398
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Babar.D6B89
ZoneAlarmHEUR:Trojan.Win32.Agent.vho
GDataGen:Variant.Babar.27529
McAfeeArtemis!ACAE61C2BD42
MAXmalware (ai score=82)
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_GEN.R035C0DJ121
YandexTrojan.GenAsa!Iq6U1y//HFE
FortinetW32/Kryptik.HISW!tr
AVGWin32:Malware-gen

How to remove Babar.27529?

Babar.27529 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment