Malware

Babar.28677 malicious file

Malware Removal

The Babar.28677 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.28677 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Babar.28677?


File Info:

name: E09E78235DE9CA00665B.mlw
path: /opt/CAPEv2/storage/binaries/e884380a7f988fb48123c0cddf8811d171dc86208c0dda258fb4afe22615e8c7
crc32: F1BADF25
md5: e09e78235de9ca00665b7d351a551129
sha1: 3f03dba47c59de54dc253844d159cb6ab97f897b
sha256: e884380a7f988fb48123c0cddf8811d171dc86208c0dda258fb4afe22615e8c7
sha512: f8abc3fe5b00b8683c5b59a438e66ddf11eebb2680a6317105e383f768e361ec39bce77a52ac0fd40b66080777349e40984584ffd3e73e221137cdb394c3fad4
ssdeep: 12288:VTzDCo5n5DPcKoggK6JvsR917qUIuJwnyfcoA8FL2f2:VjcK+Pq7hIuOnyhQf2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T183949E42B465E42BDC2112BFC831D5360357FFFEAE2A841632C997FE4CB435E6546AA0
sha3_384: e795bdd32bc7bdfdb8164620e549190d94688c50109faa254630dff34f4bfd992839a344b4680ce91c9935176db02ef3
ep_bytes: 648b3d300000000fb67f0285ff0f858b
timestamp: 2014-07-25 13:24:18

Version Info:

0: [No Data]

Babar.28677 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.28677
FireEyeGeneric.mg.e09e78235de9ca00
McAfeeGeneric Obfuscated.g
CylanceUnsafe
VIPREGen:Variant.Babar.28677
SangforTrojan.Win32.Save.a
Cybereasonmalicious.35de9c
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.T
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:Downloader.Win32.LMN.gen
BitDefenderGen:Variant.Babar.28677
NANO-AntivirusTrojan.Win32.LMN.ddtpph
SUPERAntiSpywareTrojan.Agent/Gen-Urlbot
Ad-AwareGen:Variant.Babar.28677
SophosGeneric PUA DP (PUA)
DrWebTrojan.LoadMoney.451
McAfee-GW-EditionBehavesLike.Win32.Worm.gh
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Babar.28677 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Babar.28677
AviraHEUR/AGEN.1230711
Antiy-AVLTrojan/Generic.ASMalwS.30AE
ArcabitTrojan.Babar.D7005
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
Acronissuspicious
ALYacGen:Variant.Babar.28677
MAXmalware (ai score=88)
MalwarebytesAdware.LoadMoney
RisingMalware.Undefined!8.C (TFE:3:5MrYZRYpNzQ)
IkarusTrojan.Crypt
BitDefenderThetaAI:Packer.E16371721F
PandaTrj/Genetic.gen

How to remove Babar.28677?

Babar.28677 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment