Malware

Babar.288836 removal guide

Malware Removal

The Babar.288836 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.288836 virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Babar.288836?


File Info:

name: 68AFEB0EF48B19CC8D7A.mlw
path: /opt/CAPEv2/storage/binaries/58a4f8c43e3726502dc430141b543e63ebf2abd697008856a266fcf1f2932c92
crc32: 4259CF73
md5: 68afeb0ef48b19cc8d7a50cd646948f0
sha1: 2f67183e0c4a38d04d79ffed81685555dee3b106
sha256: 58a4f8c43e3726502dc430141b543e63ebf2abd697008856a266fcf1f2932c92
sha512: d60c07dba4a42445774979d082a3925c95e371dcc0064da0d76cdaf13747b6fe241e6a17c917b86dd6d1d82ae2a06df468273cfa27609e33d54cd53051c96a71
ssdeep: 49152:mlLXOcvDQ4VTZaqdwk0c05HGiDHlCVcq8fxyI8W3J:mJXOEDjVYqdwkLcHHDFCVczfl8MJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T189D5F1C2E57340A8C5026C310CBA9E376A75FD1A1E185E977768ED193A327D4B83336B
sha3_384: 5730b49b8bc82a7ddcb97b972d3808b7eae00f6ffb482beb0686a44865065dec16159437de19a4eaf5484b0fba1be7d5
ep_bytes: 558bec6aff68c006680068cc7d450064
timestamp: 2012-07-21 05:21:12

Version Info:

FileVersion: 1.0.0.0
FileDescription: UPX压缩工具
ProductName: UPX压缩工具
ProductVersion: 1.0.0.0
CompanyName: 〆陌人泪
LegalCopyright: http://t.qq.com/vip24403413
Comments: UPX压缩工具
Translation: 0x0804 0x04b0

Babar.288836 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Babar.288836
FireEyeGeneric.mg.68afeb0ef48b19cc
ALYacGen:Variant.Babar.288836
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Babar.288836
K7AntiVirusPassword-Stealer ( 004ea1271 )
K7GWPassword-Stealer ( 004ea1271 )
CrowdStrikewin/malicious_confidence_90% (D)
CyrenW32/Trojan.CLL.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
ClamAVWin.Trojan.Flystudio-9943951-0
BitDefenderGen:Variant.Babar.288836
EmsisoftGen:Variant.Babar.288836 (B)
F-SecureTrojan:W32/DelfInject.R
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.10S0A6W
GoogleDetected
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.FlyStudio.a
Kingsoftmalware.kb.a.995
XcitiumWorm.Win32.Dropper.RA@1qraug
ArcabitTrojan.Babar.D46844
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
Cylanceunsafe
FortinetW32/CoinMiner.PHP!tr
DeepInstinctMALICIOUS

How to remove Babar.288836?

Babar.288836 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment