Malware

Babar.58156 malicious file

Malware Removal

The Babar.58156 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.58156 virus can do?

  • A file was accessed within the Public folder.
  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Babar.58156?


File Info:

name: 3F36544F9364B3F6D7DE.mlw
path: /opt/CAPEv2/storage/binaries/cb05cfb733efca19673f7987afe9824f393f776dfe08b66115da90d8db62c116
crc32: 67116DF9
md5: 3f36544f9364b3f6d7dee7d1dce68656
sha1: 62a9ebb65321ec06cc7ba331bc9f7fa618f06458
sha256: cb05cfb733efca19673f7987afe9824f393f776dfe08b66115da90d8db62c116
sha512: 1deb915e68b5209623a99b4422583dab4d90e64c9c527a97e1007ec1e45f385487c019b2d603cecfc7094e3c34285ad014052f4124986231de2d7e0dd9f9b31f
ssdeep: 1536:R7M3BhP/E9y9f/zMGv/4P6bR1ik5J/lEuU0Ay2s+eHxCEtkz30rtrN:O3BN+IfRO6bRnlZAvHcxCEtg30Bp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F1937C13B8D2C073F0160135559ACAD35B7B7A031FB9D9D7BB980A8EBA623D04676EC0
sha3_384: 5875f5a5f7ecf4a2d847cdcb5b13f85771a87957ff77651a695a5427bf48463ef108a1ef4b4e593551039e0cf3d0439a
ep_bytes: e875510000e916feffff8b442404a328
timestamp: 2013-04-02 06:46:11

Version Info:

0: [No Data]

Babar.58156 also known as:

BkavW32.AIDetectMalware
AVGWin32:DropperX-gen [Drp]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.58156
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.nm
McAfeeGenericR-GLN!3F36544F9364
Cylanceunsafe
ZillyaTrojan.Shyape.Win32.2057
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0054e5911 )
K7AntiVirusTrojan ( 0054e5911 )
BaiduWin32.Trojan.Shyape.a
VirITTrojan.Win32.DownLoad3.BIXU
SymantecTrojan.Sakurel
ESET-NOD32a variant of Win32/Shyape.G
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Scar-6745903-0
KasperskyHEUR:Trojan-Banker.Win32.BlueShai.gen
BitDefenderGen:Variant.Babar.58156
NANO-AntivirusTrojan.Win64.Agent.cysfdn
AvastWin32:DropperX-gen [Drp]
TencentTrojan-Banker.Win32.BlueShai.ha
EmsisoftGen:Variant.Babar.58156 (B)
F-SecureBackdoor.BDS/Shyape.gaffm
DrWebTrojan.DownLoader46.49440
VIPREGen:Variant.Babar.58156
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.3f36544f9364b3f6
SophosML/PE-A
IkarusTrojan.Win32.Scar
VaristW32/Agent.EVEA-1512
AviraBDS/Shyape.gaffm
Antiy-AVLTrojan/Win32.Shyape
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Sakurel.B!dha
XcitiumTrojWare.Win32.Shyape.GA@590rbc
ArcabitTrojan.Babar.DE32C
ZoneAlarmUDS:Trojan-Banker.Win32.BlueShai.gen
GDataWin32.Trojan.Sakurel.A
GoogleDetected
AhnLab-V3Trojan/Win32.Scar.R160937
VBA32BScope.Trojan.Scar
ALYacGen:Variant.Babar.58156
MAXmalware (ai score=82)
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
RisingBackdoor.FFRat!1.A74F (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Shyape.G!tr
BitDefenderThetaAI:Packer.993179FC1F
Cybereasonmalicious.f9364b
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Shyape

How to remove Babar.58156?

Babar.58156 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment