Malware

Babar.35869 removal tips

Malware Removal

The Babar.35869 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.35869 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Creates a copy of itself

How to determine Babar.35869?


File Info:

name: 25F6890C25DC888D07E7.mlw
path: /opt/CAPEv2/storage/binaries/536563ab9ecfbfbc44ecbfc1bdc63b8c371c9db493d66300f923a8e4b789761f
crc32: 06329701
md5: 25f6890c25dc888d07e78fb79d6cad15
sha1: 0c7c5a61d14ef105951f86ed4b02f843c8020d56
sha256: 536563ab9ecfbfbc44ecbfc1bdc63b8c371c9db493d66300f923a8e4b789761f
sha512: 1862516756c336681cc3a5a8931a54509628ce445cf6a65a3149a97f04a0b539ef21619e49129c90f18dd01064873dec3401aa5adba1b5e40612f98f2a19cfa1
ssdeep: 6144:kqhE2k8V+AMFjRYowicVFChuFPKfpdPgj:5W2V+VvSChiPKfpdoj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19E2412E3F57CDEC4F874FC3E403389189ED6A639BF2089AF3A64919C2F566A64341484
sha3_384: e3d005f93b8092ce7908656227c4868ecd456d89fbd6fcd195788e22f84a1d7acd1230cf5fcc80938f12825fadd2a94e
ep_bytes: 60be008040008dbe0090ffff5783cdff
timestamp: 2009-05-19 13:14:04

Version Info:

Translation: 0x0409 0x04b0
ProductName: uji
FileVersion: 2.07.0328
ProductVersion: 2.07.0328
InternalName: 7
OriginalFilename: 7.exe

Babar.35869 also known as:

LionicTrojan.Win32.Daws.b!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Babar.35869
FireEyeGeneric.mg.25f6890c25dc888d
McAfeeArtemis!25F6890C25DC
CylanceUnsafe
ZillyaTrojan.LdPinch.Win32.114
SangforTrojan.Win32.Save.a
K7AntiVirusPassword-Stealer ( 0055e3dc1 )
K7GWPassword-Stealer ( 0055e3dc1 )
Cybereasonmalicious.c25dc8
CyrenW32/Ldpinch.YPCJ-2933
SymantecTrojan.Zbot
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.AGB
Paloaltogeneric.ml
ClamAVWin.Spyware.66980-2
KasperskyTrojan-Dropper.Win32.Daws.byse
BitDefenderGen:Variant.Babar.35869
NANO-AntivirusTrojan.Win32.LdPinch.wsbh
CynetMalicious (score: 100)
APEXMalicious
Ad-AwareGen:Variant.Babar.35869
EmsisoftGen:Variant.Babar.35869 (B)
ComodoTrojWare.Win32.TrojanDownloader.Agent.BQX1@xonaq
DrWebTrojan.MulDrop.31986
VIPREGen:Variant.Babar.35869
McAfee-GW-EditionSpy-Agent.eb
SophosML/PE-A + Troj/Zbot-HU
IkarusTrojan-Dropper.Win32.Small
GDataGen:Variant.Babar.35869
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.23
KingsoftWin32.PSWTroj.LdPinch.ag.(kcloud)
ArcabitTrojan.Babar.D8C1D
ViRobotTrojan.Win32.A.PSW-LdPinch.346655[UPX]
MicrosoftTrojan:Win32/Ditertag.A
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R2366
Acronissuspicious
VBA32Trojan.VB.09
ALYacGen:Variant.Babar.35869
MalwarebytesMalware.Heuristic.1003
AvastWin32:Malware-gen
RisingTrojan.VBInject!1.6541 (CLOUD)
YandexTrojan.GenAsa!0JOkvxIdOCY
SentinelOneStatic AI – Suspicious PE
FortinetW32/VBKrypt.C!tr
AVGWin32:Malware-gen
PandaGeneric Malware

How to remove Babar.35869?

Babar.35869 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment