Malware

What is “Babar.44718 (B)”?

Malware Removal

The Babar.44718 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.44718 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Babar.44718 (B)?


File Info:

name: 5DD426798EC192D6757C.mlw
path: /opt/CAPEv2/storage/binaries/0d251dab3ea68174c573f665ce11ea17c4cc3767d05502db1d6687d5a5e20dae
crc32: 9C7EB113
md5: 5dd426798ec192d6757c9b511c093cf0
sha1: 71b32428cbb7862894f2bf058dab90bd8e995bd3
sha256: 0d251dab3ea68174c573f665ce11ea17c4cc3767d05502db1d6687d5a5e20dae
sha512: 927e4973e3262c36fdec9c0fa54b64a44d263a2aeb955c12d255128ffb66c9edd3b963e0f3af56ccc8e46e5270f50c9adc2a71cfc232dae36d8971956b772c95
ssdeep: 49152:nqeNVaW69e6i/Sq5maqPKtEucspQi+5J2k6FEwfkkhXD3/9et:qE9zbajKt8spEHmEwfkoTlQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T163D5E12FF268643ED86E0A3145B392606E3B7B92B49E4C1E03F0591DDF654711E3F92A
sha3_384: f2714cf85c9be4509a477f68f67e8d32ff7c69939e2526cc2131ca66e6b96298181e418c5b25e881bd747879fc9cc852
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2020-05-21 05:56:23

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: 武汉乐享其识科技有限公司
FileDescription: 速捷密码工具 安装程序
FileVersion: 1.0.1.24
LegalCopyright: 版权所有 ©2022 武汉乐享其识科技有限公司
OriginalFileName:
ProductName: 速捷密码工具
ProductVersion: 1.0.1.24
Translation: 0x0000 0x04b0

Babar.44718 (B) also known as:

MicroWorld-eScanGen:Variant.Babar.44718
FireEyeGen:Variant.Babar.44718
ALYacGen:Variant.Babar.44718
K7AntiVirusTrojan ( 0056ef6d1 )
K7GWTrojan ( 0056ef6d1 )
CyrenW32/Agent.EJW.gen!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.ACAV
Kasperskynot-a-virus:HEUR:AdWare.Win32.Burden.gen
BitDefenderGen:Variant.Babar.44718
AvastWin32:MalwareX-gen [Trj]
TencentMalware.Win32.Gencirc.10d06cb6
Ad-AwareGen:Variant.Babar.44718
SophosGeneric Reputation PUA (PUA)
F-SecureHeuristic.HEUR/AGEN.1211299
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
EmsisoftGen:Variant.Babar.44718 (B)
IkarusTrojan.Win32.Agent
GDataGen:Variant.Babar.44718
AviraHEUR/AGEN.1211299
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Burden.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.R499147
Acronissuspicious
McAfeeArtemis!5DD426798EC1
MalwarebytesMalware.AI.928136551
RisingAdware.Agent!1.DD00 (CLASSIC)
YandexPUA.Burden!6Ks4oBQif84
MAXmalware (ai score=81)
AVGWin32:MalwareX-gen [Trj]
CrowdStrikewin/grayware_confidence_70% (D)

How to remove Babar.44718 (B)?

Babar.44718 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment