Malware

What is “Babar.27963 (B)”?

Malware Removal

The Babar.27963 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.27963 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz

How to determine Babar.27963 (B)?


File Info:

crc32: 276C0A7C
md5: e5b21a3a7853fd12c8fa65bb1abec7f9
name: E5B21A3A7853FD12C8FA65BB1ABEC7F9.mlw
sha1: 083d0f8125eefa13cf340ebe3a4ff31c5c30f7fe
sha256: eb79c07d2967248ea62bfcf9698c175b3208ee2a8b69beef9a9ed0994315c91a
sha512: 0be09389b49e4cdaa7a57bbbce863f8eb6b7898958999bdb6b97a001ac6fd608eaa890c95f9bbf3394b318a2ccdbda9571e6f479fb25bebc208b293fa8f6adb0
ssdeep: 6144:bVk3OQ3owYCvgC/VeFnlL/ZXWxZhAkH7knGyHM:bVOOD7azGnlL/ZXWpZHI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: fogsmoageke.emi
ProductVersion: 9.51.22.12
Copyright: Copyrighz (C) 2020, fodkageta
Translation: 0x0182 0x0102

Babar.27963 (B) also known as:

K7AntiVirusTrojan ( 0056f9be1 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/GandCrab.b04e6ed4
K7GWTrojan ( 0056f9be1 )
CyrenW32/Kryptik.EUY.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.HMBH
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
BitDefenderTrojan.GenericKD.46774799
MicroWorld-eScanTrojan.GenericKD.46774799
Ad-AwareTrojan.GenericKD.46774799
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34058.tq0@aWuJtBli
TrendMicroMal_HPGen-50
McAfee-GW-EditionBehavesLike.Win32.Emotet.fc
FireEyeGeneric.mg.e5b21a3a7853fd12
EmsisoftGen:Variant.Babar.27963 (B)
SentinelOneStatic AI – Malicious PE
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataMSIL.Trojan-Stealer.NetSteal.B52V1A
Acronissuspicious
McAfeeArtemis!E5B21A3A7853
MAXmalware (ai score=85)
VBA32Trojan.MSIL.RedLine.Heur
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B40D (CLASSIC)
IkarusWin32.Outbreak
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HMBH!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Heur.Generic.HwoCM2cA

How to remove Babar.27963 (B)?

Babar.27963 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment