Malware

Babar.38298 malicious file

Malware Removal

The Babar.38298 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.38298 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Babar.38298?


File Info:

name: 624129C9CF4B12EBE598.mlw
path: /opt/CAPEv2/storage/binaries/31cc4547a3b310f178d80c13c3c1b515e88a924e486dac15d273405e69aa1d6f
crc32: 585FAA61
md5: 624129c9cf4b12ebe59865ddd7e44756
sha1: ad769ba2574bbd7ade5f80a71be4058dce6f7d61
sha256: 31cc4547a3b310f178d80c13c3c1b515e88a924e486dac15d273405e69aa1d6f
sha512: 2cccb4908006b526b5008e0c2b0674224f6606b72711ae7e7df10b315a20d580ecae01fc019c4453eeadffe8de9c531f63c22f8bc88ab78870261b66a2edf106
ssdeep: 768:sUqYVDkoq12h3QXKScS1PdlmTA5xB8gsbn8xhsu350Zi9zuJN:srYVDkoq12h3QXD11esj8x8xhsuxzub
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T106F26C83E7E4C472F5B2DEB89D74C11A6D3F3EA22D35805E9194E98D1C727D0A92831B
sha3_384: 43aa028f1d5a35076e153fca6541fcddf346ed3b7b62b572f076628e26a2da85e30b71b48a12398bb4afa6c50971528d
ep_bytes: 558bec83c4e8535633c08945ec8945e8
timestamp: 1992-06-19 22:22:17

Version Info:

Comments:
CompanyName: 360.cn
FileDescription: 360杀毒 主程序
FileVersion: 2, 0, 0, 1330
InternalName: 360sd.exe
LegalCopyright: (C)360.cn Inc.All Rights Reserved.
LegalTrademarks:
OriginalFilename: 360sd.exe
PrivateBuild:
ProductName: 360杀毒
ProductVersion: 2, 0, 0, 1330
SpecialBuild:
Translation: 0x0804 0x04b0

Babar.38298 also known as:

CynetMalicious (score: 99)
FireEyeGeneric.mg.624129c9cf4b12eb
VIPREGen:Variant.Babar.38298
K7AntiVirusVirus ( 7000000f1 )
BitDefenderGen:Variant.Babar.38298
K7GWVirus ( 7000000f1 )
Cybereasonmalicious.9cf4b1
CyrenW32/Hupigon.XNJH-2137
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Raxtip.D
APEXMalicious
NANO-AntivirusTrojan.Win32.Delf.fiijiu
MicroWorld-eScanGen:Variant.Babar.38298
AvastWin32:Delf-SFH [Trj]
Ad-AwareGen:Variant.Babar.38298
EmsisoftGen:Variant.Babar.38298 (B)
DrWebTrojan.Siggen11.64588
TrendMicroBKDR_HUPIGON.GEN
Trapminemalicious.high.ml.score
AviraTR/Delf.Agent.iirjp
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.81D8
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Babar.D959A
GDataGen:Variant.Babar.38298
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C2555944
BitDefenderThetaGen:NN.ZelphiF.34646.cG2@aO!llyfb
ALYacGen:Variant.Babar.38298
VBA32suspected of Trojan.Downloader.gen
CylanceUnsafe
TrendMicro-HouseCallBKDR_HUPIGON.GEN
YandexTrojanSpy.Agent!d/veGs/pY08
IkarusTrojan.Win32.Genome
AVGWin32:Delf-SFH [Trj]
PandaTrj/GdSda.A

How to remove Babar.38298?

Babar.38298 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment