Malware

Babar.56110 (B) removal tips

Malware Removal

The Babar.56110 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.56110 (B) virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Babar.56110 (B)?


File Info:

name: EB7E63E15CA503F61269.mlw
path: /opt/CAPEv2/storage/binaries/9da54b6bda806d558eece2cd54db627a1f80e3785fd6a2f7eb997a424da5d328
crc32: 3FD24F3E
md5: eb7e63e15ca503f61269da70cdb03756
sha1: 9d4c2f589649d86a3c85482a2c37ad1a2a936977
sha256: 9da54b6bda806d558eece2cd54db627a1f80e3785fd6a2f7eb997a424da5d328
sha512: 36a2b82733b6c2d34a990783f5d11986b49b410054348b39c8cf3769ba843a29975bf5fee7248d7cb19e1b98de64c423d74257ed413b165c83364385fdde2470
ssdeep: 49152:DKu86w3iZjuzwZj3F05B3+s8KuqGaX0ToIBAUZLY:ODF3iBuEZS5eJBAUZL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T196C5D001F3E281F5E6562170647A2B3F9939EE451F1485C373E4FE5D1DB23E09ABA20A
sha3_384: ab4aa361d1311848b54c28501dd5a2153e8d2dcd34780eba0ea98c62391184de2634e0a750ad18a2f626ba9d60601c1a
ep_bytes: 558bec6aff68d8066400688475490064
timestamp: 2022-06-25 06:00:50

Version Info:

0: [No Data]

Babar.56110 (B) also known as:

BkavW32.AIDetect.malware2
LionicHeuristic.File.Generic.00×1!p
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.56110
FireEyeGeneric.mg.eb7e63e15ca503f6
McAfeeArtemis!EB7E63E15CA5
CylanceUnsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
AlibabaTrojan:Win32/Redcap.b861647f
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34682.BsW@aOmEiqbb
CyrenW32/S-965fe2e2!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0WIJ22
Paloaltogeneric.ml
KasperskyHEUR:Trojan-GameThief.Win32.OnLineGames.gen
BitDefenderGen:Variant.Babar.56110
AvastWin64:Trojan-gen
TencentWin32.Trojan-GameThief.Onlinegames.Snkl
Ad-AwareGen:Variant.Babar.56110
SophosGeneric ML PUA (PUA)
ComodoWorm.Win32.Dropper.RA@1qraug
VIPREGen:Variant.Babar.56110
TrendMicroTROJ_GEN.R002C0WIJ22
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Babar.56110 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1TYMTF4
JiangminTrojanDownloader.Upatre.agsy
GoogleDetected
AviraTR/Redcap.jlcoe
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5241210
ALYacGen:Variant.Babar.56110
MalwarebytesTrojan.MalPack.FlyStudio
FortinetW32/CoinMiner.65CA!tr
AVGWin64:Trojan-gen
Cybereasonmalicious.89649d

How to remove Babar.56110 (B)?

Babar.56110 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment