Malware

Should I remove “Babar.371897”?

Malware Removal

The Babar.371897 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.371897 virus can do?

  • Sample contains Overlay data
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Babar.371897?


File Info:

name: 23D29F7E0D1A5C175D19.mlw
path: /opt/CAPEv2/storage/binaries/a012f42cfd0678f74f510e1adda98fbdf00e0f0876d9fb3b4e3b0c73fd132412
crc32: F6591C73
md5: 23d29f7e0d1a5c175d19b2bfdf019ec9
sha1: 0c4f8601edaf41632dba391977516b89ae84da35
sha256: a012f42cfd0678f74f510e1adda98fbdf00e0f0876d9fb3b4e3b0c73fd132412
sha512: 384125921a9cfdb27d38a90acda101af41649f0cff65b2ce453f4245b54bc11fabb7d2ffd9b1aff8cfeddb18071149ddffab307e15a9b0d0c0b10664eb4df37e
ssdeep: 98304:srPq07gsH5kGOzgRiNxmdKeClNBB1LUoxA/6SDmrZRJ:srT7gbGOzbEUB/woxb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10C3633E87A2EC956F150B3F084D4256A9EC4A581BE74CD0E9D9B5630A237EBF3D4321C
sha3_384: f257e1ae0665468fb6e099bad3f5c57d0a5e544e4a0e2784b0209ecdc39370b52a439c05acff1979b446ed77d534a918
ep_bytes: e84b0100005389e3538b73088b7b10fc
timestamp: 2012-06-26 10:32:30

Version Info:

Comments:
CompanyName: 金山软件股份有限公司
FileDescription: JxOnline Client
FileVersion: 3, 0, 0, 6
InternalName: Game
LegalCopyright: 版权所有 (C) 1995-2004 金山软件股份有限公司
LegalTrademarks:
OLESelfRegister:
OriginalFilename: Game.exe
PrivateBuild:
ProductName: SwordOnline
ProductVersion: 3.00.00.2003
SpecialBuild:
Translation: 0x0804 0x04b0

Babar.371897 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Babar.371897
FireEyeGeneric.mg.23d29f7e0d1a5c17
SkyhighBehavesLike.Win32.Generic.rc
ALYacGen:Variant.Babar.371897
MalwarebytesTrojan.MalPack.Themida
K7AntiVirusTrojan ( 005203381 )
K7GWTrojan ( 005203381 )
ArcabitTrojan.Babar.D5ACB9
Elasticmalicious (high confidence)
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002H09LL23
BitDefenderGen:Variant.Babar.371897
EmsisoftGen:Variant.Babar.371897 (B)
VIPREGen:Variant.Babar.371897
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Babar.371897
CynetMalicious (score: 100)
McAfeeArtemis!23D29F7E0D1A
GoogleDetected
MAXmalware (ai score=89)
Cylanceunsafe
ZonerProbably Heur.ExeHeaderL
RisingTrojan.Generic@AI.100 (RDML:5rbjNnZB9tbLY9sf7yj15g)
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.216064600.susgen
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Babar.Gen

How to remove Babar.371897?

Babar.371897 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment