Malware

Babar.45049 (file analysis)

Malware Removal

The Babar.45049 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.45049 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Babar.45049?


File Info:

name: F7BBA81CF89F5D9C3434.mlw
path: /opt/CAPEv2/storage/binaries/14c8f443f671f92d233b83d6f2ce42af48eb5371cb4d06c19ddbabe923beade2
crc32: CE1B4729
md5: f7bba81cf89f5d9c3434685f8d6b47c8
sha1: a6001d9361f89c1b771a0b89d1f5866de6e25e72
sha256: 14c8f443f671f92d233b83d6f2ce42af48eb5371cb4d06c19ddbabe923beade2
sha512: 7c17a9037420366f64ee717899d5f4a42b5a9c5fd2feedd1cc79519d9b07ade87d6b16abf4d2ac8203fd393aad060e1e94651dec5381985654b9d60742b10a5f
ssdeep: 49152:wg3kXf3pgz/SsMcO1fZkKLy1zpslsqzzqqALm9axp6XgcBr+wp7Cj4KGuT+X1q7e:wg3kXPyeLcQzzqqALm9HlvI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13D462851FDDB50BAEA03193004A792BF67306D098B39CBC7DA107F6AE8776D10E36619
sha3_384: 9a65d1dbbe4d030f493718b00245e9d3a85243be5e4e7e5207aa038af8f08f137156acee1161f1022a97c4d6d863bb09
ep_bytes: e96bddffffcccccccccccccccccccccc
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Babar.45049 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agent.Y!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.45049
ALYacGen:Variant.Babar.45049
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2899970
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005958521 )
BitDefenderGen:Variant.Babar.45049
K7GWTrojan ( 005958521 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Babar.DAFF9
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of WinGo/Agent.HV
CynetMalicious (score: 100)
APEXMalicious
KasperskyTrojan-Downloader.Win32.Agent.xyaflc
AlibabaBackdoor:Win32/Goshell.190517
RisingTrojan.Generic@AI.91 (RDML:I1T4C4iv0EGyfRc2IMWWWA)
Ad-AwareGen:Variant.Babar.45049
SophosGeneric ML PUA (PUA)
VIPREGen:Variant.Babar.45049
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.f7bba81cf89f5d9c
EmsisoftGen:Variant.Babar.45049 (B)
IkarusTrojan.WinGo.Agent
AviraTR/Dldr.Agent.fvvwl
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.330C
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Babar.45049
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5219307
McAfeeGenericRXAA-AA!F7BBA81CF89F
MalwarebytesMalware.Heuristic.1006
TrendMicro-HouseCallTROJ_GEN.R002H0CIK22
TencentWin32.Trojan-Downloader.Agent.Kjgl
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.185087807.susgen
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34682.@FW@aeC3HZki
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Babar.45049?

Babar.45049 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment