Malware

What is “Babar.441403”?

Malware Removal

The Babar.441403 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.441403 virus can do?

  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Babar.441403?


File Info:

name: D1E55AC44BCFD85ACE20.mlw
path: /opt/CAPEv2/storage/binaries/d0d0137e834ae8f01b62ffc8d5b1600dfa46ef9f8e336824333a58631f3524a5
crc32: AEF0010B
md5: d1e55ac44bcfd85ace20c75db64ebd92
sha1: 1a18348b570cedbb7b74a3b0873a288d4bdc57aa
sha256: d0d0137e834ae8f01b62ffc8d5b1600dfa46ef9f8e336824333a58631f3524a5
sha512: c3f52cf61960d86c5ced6f9655220334ce29145f1587addfcfb32629e3d775eb93b5facc338552313559f0ba3a8138864b741efdea88cc274edd39d0b6e1b266
ssdeep: 12288:2XM+XeFbEqc6FA2DWUnVYfMAmSpUi0WDo10XHACsmqpFMsiP:2c+Oa6FA2DW+YMAylcU0XHXD8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A5F45C22B2E18437E1732B789C2B91A59836BF103E38DD4A3BE52D0C4F356917D69397
sha3_384: 788060be26e6339d83cc07efab0a451640bc2b2776456d96882609f2e57f500d6e01ecffa1ac41b7878176ce8979275b
ep_bytes: 558bec83c4f0b8cc9f4800e884bff7ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Babar.441403 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Buzy.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader2.64248
CynetMalicious (score: 100)
FireEyeGeneric.mg.d1e55ac44bcfd85a
Cylanceunsafe
VIPREGen:Variant.Babar.441403
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZelphiF.36744.SOW@aWcIa5mO
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Trojan.Downloader-67956
BitDefenderGen:Variant.Babar.441403
NANO-AntivirusTrojan.Win32.TrjGen.dtrbxx
MicroWorld-eScanGen:Variant.Babar.441403
AvastWin32:Downloader-HUA [Trj]
EmsisoftGen:Variant.Babar.441403 (B)
F-SecureTrojan.TR/Buzy.263168
ZillyaDownloader.Delf.Win32.28858
TrendMicroTROJ_AGENT_019414.TOMB
Trapminemalicious.high.ml.score
SophosMal/Troxen-F
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Babar.441403
JiangminTrojanDownloader.Generic.bom
GoogleDetected
AviraTR/Buzy.263168
Antiy-AVLTrojan[Downloader]/Win32.Genome
Kingsoftmalware.kb.a.823
XcitiumTrojWare.Win32.TrojanDownloader.Delf.QPM@74qtq0
ArcabitTrojan.Babar.D6BC3B
MicrosoftTrojanDownloader:Win32/Delf.QX
VaristW32/Agent.JI.gen!Eldorado
AhnLab-V3Win-Trojan/Overtls17.Gen
VBA32BScope.TrojanBanker.Banker
ALYacGen:Variant.Babar.441403
MAXmalware (ai score=87)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_AGENT_019414.TOMB
RisingDownloader.Agent!1.9D4D (CLASSIC)
YandexTrojan.GenAsa!8P1mgkiTzgU
IkarusGen.Variant.Buzy
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Delf.BHO!tr.dldr
AVGWin32:Downloader-HUA [Trj]
Cybereasonmalicious.b570ce
DeepInstinctMALICIOUS

How to remove Babar.441403?

Babar.441403 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment