Malware

Babar.50362 removal guide

Malware Removal

The Babar.50362 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.50362 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Persian (Iran)
  • Unconventionial language used in binary resources: Farsi
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects BullGuard Antivirus through the presence of a library
  • Detects Sandboxie through the presence of a library
  • Detects SunBelt Sandbox through the presence of a library

How to determine Babar.50362?


File Info:

name: 317B39FC12C3B32E6C20.mlw
path: /opt/CAPEv2/storage/binaries/79fcb7e53b51655f5a7c86714f0916468c01a26de168c40c5c5eb47b5648abce
crc32: FD341B09
md5: 317b39fc12c3b32e6c2082cf47d16e69
sha1: 5d6169d05d892118bcd762760f9a3fd540ce0180
sha256: 79fcb7e53b51655f5a7c86714f0916468c01a26de168c40c5c5eb47b5648abce
sha512: 29dc8d28ff376665dfb711eba271ac1532e94579ab3c3eb9597f9819a2a06d0a83d3d7d4895671aa067d104a9eb1bb75d82c9630babb46aa5bb896c3dd35f08e
ssdeep: 24576:VGx/yu1WMR7xzlkHW3MWwrMF9c6xycF5VCCXMUEahvn:VGX1VedYF9cvcD0qMLy/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12B45012C9D868CA1CE4686B59D9AC6DA2D3F651088F18C0B117F7D26EE2CFBD351418F
sha3_384: 848a68d10d06472dfd4e90f5465e2602a6a22318150731be085861457e5b235f5ad73c94c4a0ada2388433b6942e587c
ep_bytes: e87f280000e989feffff8bff558bec8b
timestamp: 2022-05-08 15:48:48

Version Info:

FileVersion: 76.17.100.38
LegalCopyright: Copyright (C) 2013-2022 by Nilegate App All Rights Reserved.
ProductVersion: 49.68.7.50
Translation: 0x0429 0x0429

Babar.50362 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
SymantecML.Attribute.HighConfidence
APEXMalicious
BitDefenderGen:Variant.Babar.50362
MicroWorld-eScanGen:Variant.Babar.50362
RisingTrojan.Generic@AI.90 (RDML:PSy9HfdFOxhk4az330Cs6g)
Ad-AwareGen:Variant.Babar.50362
SophosGeneric ML PUA (PUA)
FireEyeGeneric.mg.317b39fc12c3b32e
EmsisoftGen:Variant.Babar.50362 (B)
IkarusTrojan.Win32.Ranumbot
GDataGen:Variant.Babar.50362
MAXmalware (ai score=88)
ArcabitTrojan.Babar.DC4BA
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ALYacGen:Variant.Babar.50362
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGFileRepMalware [Misc]
AvastFileRepMalware [Misc]

How to remove Babar.50362?

Babar.50362 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment