Malware

How to remove “Babar.401854”?

Malware Removal

The Babar.401854 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.401854 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Babar.401854?


File Info:

name: DD86EB6C52E36543E938.mlw
path: /opt/CAPEv2/storage/binaries/79ee5d8b0e529c1053b3423551722376ccdb9cc1fc2d37a93efd18ff1c07ca36
crc32: 8B9F8E75
md5: dd86eb6c52e36543e93804a75d59fcdd
sha1: 6c81c329543e15377dd7ba299e989a9d477e82af
sha256: 79ee5d8b0e529c1053b3423551722376ccdb9cc1fc2d37a93efd18ff1c07ca36
sha512: bca4fc374fd73f81951294599f23d14553779dbf2fa1f2e5cd6457744c2c014dd2ff57df442084a13956118624d1fa95d2580ebef01eeb4d3665a0ed2327934a
ssdeep: 6144:T8LxBSI9gVlo+7EbM/J1D3AZ3TLn6s6cCbyXtSkckXnloPWE9RVZ1uASqnAPoe5w:PI6CY/JUDOs6c4mgk1XloPWEfVPEx5MZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FF8412D13AFC98B7D862C6B0023ED824DE364CB54125499B83597A77AEF1AD3460337B
sha3_384: 066478ddbda3f1141a0cf979a7f45083ec492f0d4984252c99b1ec5973f6b21c2851ca1e14edd25a9e502bb1a3c33d7e
ep_bytes: 81ec840100005355565733db68018000
timestamp: 2016-04-02 03:20:13

Version Info:

CompanyName: objective
FileDescription: deteriorate
FileVersion: 44.4.0.7
ProductVersion: 44.4.0.7
Translation: 0x0409 0x04e4

Babar.401854 also known as:

BkavW32.Common.9DB2CDD7
LionicTrojan.Win32.Strab.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.401854
SkyhighBehavesLike.Win32.Generic.fc
ALYacGen:Variant.Babar.401854
MalwarebytesTrojan.MalPack
VIPREGen:Variant.Babar.401854
SangforTrojan.Win32.Formbook.Vxqc
K7AntiVirusTrojan ( 005af1011 )
BitDefenderGen:Variant.Babar.401854
K7GWTrojan ( 005af1011 )
ArcabitTrojan.Babar.D621BE
BitDefenderThetaGen:NN.ZexaF.36744.kqW@a0FQ!Tce
SymantecTrojan Horse
ESET-NOD32Win32/Formbook.AA
KasperskyHEUR:Trojan.Win32.Strab.gen
AlibabaTrojan:Win32/Strab.20409a87
NANO-AntivirusTrojan.Win32.Strab.kewtxl
ViRobotTrojan.Win.Z.Strab.373292
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Strab.Rqil
EmsisoftGen:Variant.Babar.401854 (B)
F-SecureTrojan.TR/Injector.dsbvb
DrWebTrojan.Loader.1901
ZillyaTrojan.Formbook.Win32.7893
TrendMicroTROJ_GEN.R002C0PLB23
FireEyeGeneric.mg.dd86eb6c52e36543
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
MAXmalware (ai score=88)
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Injector.dsbvb
VaristW32/Injector.BTJ.gen!Eldorado
Antiy-AVLTrojan/Win32.Wacatac
KingsoftWin32.Trojan.Strab.gen
XcitiumMalware@#36qxi8sy9y0zo
MicrosoftTrojan:Win32/Leonem
ZoneAlarmHEUR:Trojan-Spy.Win32.Noon.gen
GDataGen:Variant.Babar.401854
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5559436
McAfeeRDN/formbook
VBA32BScope.Trojan.Strab
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0PLB23
RisingTrojan.Injector!8.C4 (TFE:5:aIQII0Q35JI)
YandexTrojan.Igent.b1lqZ8.13
FortinetNSIS/Agent.DCAC!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Babar.401854?

Babar.401854 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment