Malware

Babar.402564 malicious file

Malware Removal

The Babar.402564 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.402564 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Babar.402564?


File Info:

name: 8171F622ADCABEF3D3E4.mlw
path: /opt/CAPEv2/storage/binaries/7decf7e692362cf83644d4c58ab525571de973ee946032f3e747a1646debbc12
crc32: 0670BB31
md5: 8171f622adcabef3d3e4d7707f2ef737
sha1: 7cf4c0c13ee2a194fe96ffb96b1ff94ec556a678
sha256: 7decf7e692362cf83644d4c58ab525571de973ee946032f3e747a1646debbc12
sha512: 33b63ca60a8b32ce8e1dd64c06338d41cbaec50d6c19fd522ef38b12d7fb8c2fd1cf3af393d0d9816f4d9f8e504d82eb4bea523edfa1dc5ddfda6b31f5929156
ssdeep: 3072:1ORoLsKG5T9wdnIA+fKNGUrqkfinep+kkOPqSnXxvQY2YhwXBD+ftFWVN:5sKkP7ArhXxvQYVf/8N
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AFF32836BE4EE070F06104357D49D6A7786638B43220544BFBC96F2DEA3A3B6D621B17
sha3_384: e94e43bbe39de2429ef0aa78cb48dfa271ea075291b5db34538054af7cd388562cebd0381c2de8d7b834e10b3874eef7
ep_bytes: 558bec81eca000000053565756575251
timestamp: 2002-10-02 09:13:17

Version Info:

Translation: 0x0804 0x04b0
CompanyName: Nanjing
ProductName: 工程1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: D-10vb
OriginalFilename: D-10vb.exe

Babar.402564 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
CAT-QuickHealTrojan.Generic.20771
SkyhighBehavesLike.Win32.Sakula.cm
ALYacGen:Variant.Babar.402564
MalwarebytesMalware.AI.1127700498
VIPREGen:Variant.Babar.402564
SangforTrojan.Win32.Agent.V49i
Cybereasonmalicious.13ee2a
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Babar.402564
NANO-AntivirusTrojan.Win32.WBNA.cyfaqz
MicroWorld-eScanGen:Variant.Babar.402564
RisingTrojan.Generic@AI.87 (RDML:kVX2M/fBPINrC0x6JFhn/g)
EmsisoftGen:Variant.Babar.402564 (B)
F-SecureHeuristic.HEUR/AGEN.1336408
TrendMicroTROJ_GEN.R03BC0PJV23
FireEyeGeneric.mg.8171f622adcabef3
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Babar.402564
JiangminPacked.PePatch.nbs
GoogleDetected
AviraHEUR/AGEN.1336408
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Wacatac
Kingsoftmalware.kb.a.780
ArcabitTrojan.Babar.D62484
MicrosoftTrojan:Win32/Wacatac.A!ml
VaristW32/VB.MK.gen!Eldorado
McAfeeGenericRXAX-GA!8171F622ADCA
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R03BC0PJV23
IkarusWorm.Win32.VB
MaxSecureTrojan.Malware.220002193.susgen
FortinetW32/PossibleThreat
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Babar.402564?

Babar.402564 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment