Malware

Babar.44762 removal guide

Malware Removal

The Babar.44762 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.44762 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Babar.44762?


File Info:

name: 0218A26BC215E1147DF0.mlw
path: /opt/CAPEv2/storage/binaries/5f9f5495ef5540a7899fe3cb088202406cac63dfb84dd8ec0c1c73fb7f988710
crc32: 6AD27AC8
md5: 0218a26bc215e1147df0930d5dede9d7
sha1: 0b050cd748dc4b89f2150740286e8f4210c52edd
sha256: 5f9f5495ef5540a7899fe3cb088202406cac63dfb84dd8ec0c1c73fb7f988710
sha512: 9082b8d29832e26dce50fc60ad2ef18ab1326c734b16774851ea154d239373679d220ad769fbc55d4d37a1b99fb09a7fc252c07f55c2e4d2d63e08533b5e5cc8
ssdeep: 768:a/y5unxgSHB9L505iSxuBEP2Wp6M8Rcg/vPIk/SgzeMZruqft:aK5JSh9m5iAue34M/g/vAl3MX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AA33E0809257D9C3E462EB3D910BEB38666558485B1ED706FB04772FCEF22F34642B85
sha3_384: 90af962ed2555346e278ecd45932fdef20ea5fbba3b103b18b879f101ecba1e7e9f96b578d7e298a0d933666cb9b965c
ep_bytes: b8cc4842005064ff3500000000648925
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Babar.44762 also known as:

BkavW32.AIDetect.malware1
LionicHeuristic.File.Generic.00×1!p
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Babar.44762
FireEyeGeneric.mg.0218a26bc215e114
CAT-QuickHealDownloader.Banload.26697
ALYacGen:Variant.Babar.44762
CylanceUnsafe
VIPREGen:Variant.Babar.44762
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
AlibabaTrojanDownloader:Win32/Banload.421400eb
K7GWTrojan-Downloader ( 0055e3da1 )
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/NewMalware-LSU-based!Maximu
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Banload.OHG
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Scar.oaso
BitDefenderGen:Variant.Babar.44762
NANO-AntivirusTrojan.Win32.Delf.duylx
AvastFileRepMalware [Trj]
TencentWin32.Trojan.Scar.Kajl
Ad-AwareGen:Variant.Babar.44762
EmsisoftGen:Variant.Babar.44762 (B)
ComodoTrojWare.Win32.Downloader.Delf.frei@2t3lu7
DrWebTrojan.DownLoad1.39525
ZillyaDownloader.Delf.Win32.16749
McAfee-GW-EditionBehavesLike.Win32.Downloader.qc
Trapminemalicious.high.ml.score
SophosMal/DelpDldr-D
IkarusTrojan-Dropper.Delf
GDataGen:Variant.Babar.44762
JiangminTrojanDownloader.Delf.aaob
WebrootW32.InfoStealer.Bancos
AviraTR/Dldr.Delphi.Gen
Antiy-AVLTrojan/Generic.ASMalwS.330C
ArcabitTrojan.Babar.DAEDA
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Banload.R41470
McAfeeArtemis!0218A26BC215
MAXmalware (ai score=100)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.Heuristic.1001
RisingDownloader.Banload!8.15B (CLOUD)
YandexTrojan.GenAsa!/zGBdD8F1lc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Magania.IDPJ!tr
BitDefenderThetaAI:Packer.CCF6991E1F
AVGFileRepMalware [Trj]
Cybereasonmalicious.bc215e
PandaTrj/CI.A

How to remove Babar.44762?

Babar.44762 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment