Malware

Babar.37633 removal tips

Malware Removal

The Babar.37633 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.37633 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Manipuri
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family

How to determine Babar.37633?


File Info:

name: B4D9AE71228F8BCAB781.mlw
path: /opt/CAPEv2/storage/binaries/f5598eb9060bd2a98f4d37c458f525b2587edf21f598512a6b24bb699db415a1
crc32: A5175159
md5: b4d9ae71228f8bcab7816f05abd6ae93
sha1: 58c1650e5232f663bbf6f8fa31f12e555fa0a03c
sha256: f5598eb9060bd2a98f4d37c458f525b2587edf21f598512a6b24bb699db415a1
sha512: 662e6434f2cd0ba0aa1526d4b16785b75dd08297afd7ebd26f397ee600a8afb52e3fb80fc5b90bf406b21dc78782e9d26514f456327bfd45302df8fa21762a57
ssdeep: 6144:TJoiw7kwi3Zp6p1fWDIL5A5Qh1vqKRrLm1mFodBq/C88UMGMkigau6:TJ6kwi3Zp6rfWDILUQXS8qB8LMGMB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10694DF6D72E1C431D1A75E305436DFA11A7FBC22683095CBE2A47B6A2E313C199B631F
sha3_384: af4801984b34fc9d384fe8a22126b3dc484ef28db6319e52fe1dfe609c5d8351f9300ef286a17334c11218100cee3a3c
ep_bytes: e8fc400000e989feffff8bff558bec51
timestamp: 2021-09-19 03:48:58

Version Info:

FileVersion: 4.75.86.8
Copyrighz: Copyright (C) 2022, pazkarte
ProjectVersion: 98.81.74.73

Babar.37633 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen17.42147
MicroWorld-eScanGen:Variant.Babar.37633
FireEyeGeneric.mg.b4d9ae71228f8bca
CAT-QuickHealRansom.Stop.P5
McAfeePacked-GDT!B4D9AE71228F
MalwarebytesTrojan.MalPack.GS
VIPREGen:Variant.Babar.37633
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00591a951 )
K7GWTrojan ( 00591a951 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Kryptik.GOQ.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.HPGI
APEXMalicious
ClamAVWin.Packed.Agen-9953297-0
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Babar.37633
AvastWin32:AceCrypter-T [Cryp]
TencentTrojan-Spy.Win32.Stealer.16000356
Ad-AwareGen:Variant.Babar.37633
SophosMal/Generic-R + Troj/Krypt-IR
ZillyaTrojan.Kryptik.Win32.3746999
TrendMicroTROJ_GEN.R007C0DI422
McAfee-GW-EditionPacked-GDT!B4D9AE71228F
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Babar.37633 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Strab.ati
GoogleDetected
AviraHEUR/AGEN.1249897
MicrosoftTrojan:Win32/Raccrypt.GY!MTB
GDataWin32.Trojan.PSE.15PZVJ0
CynetMalicious (score: 100)
AhnLab-V3Packed/Win.GEE.R485681
Acronissuspicious
VBA32BScope.Malware-Cryptor.Hlux
ALYacGen:Variant.Babar.37633
MAXmalware (ai score=87)
TrendMicro-HouseCallTROJ_GEN.R007C0DI422
RisingTrojan.Generic!8.C3 (TFE:5:URYDGkU5cYU)
IkarusTrojan-Ransom.StopCrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FTKF!tr
AVGWin32:AceCrypter-T [Cryp]
Cybereasonmalicious.e5232f
PandaTrj/Genetic.gen

How to remove Babar.37633?

Babar.37633 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment