Malware

Babar.61480 malicious file

Malware Removal

The Babar.61480 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.61480 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Babar.61480?


File Info:

name: BBD7EF2CFC7F71CDE851.mlw
path: /opt/CAPEv2/storage/binaries/b284307ef3d1dd295cf83c957bf56d281792d2a5b5e95aea1839c0bb6706c2f5
crc32: D58E9B63
md5: bbd7ef2cfc7f71cde851a71fdd7569b1
sha1: 03fe138710f8d0dae08196c9adca40fd2e449bd3
sha256: b284307ef3d1dd295cf83c957bf56d281792d2a5b5e95aea1839c0bb6706c2f5
sha512: a03c432f57147d79698ab3eae0c6fa6091a10c21209f0c6a8240f49319b657360d9b7bf6e3549d712726c65aec71472908473100fd419aefcb84c915d05b06d3
ssdeep: 1536:AoUCwsMO4UNsqsoRfkiz55SN7sfOBgX2:QCMO4USqsoRfkiz5ITK2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C2435C93E2101DE1F0565D715A3B2FB68A3B4CB52A50894B8F5CFE0DACB3A40651B32F
sha3_384: a8a4f4fa3dbbe027d84a9782feac65c3cdf6c93d15bd68a24f5b6f89e48a8355b274742da4548ad7eb8c8b198f7be5d4
ep_bytes: 558bec6aff6898554000685048400064
timestamp: 2009-11-21 05:33:30

Version Info:

0: [No Data]

Babar.61480 also known as:

LionicTrojan.Win32.Agent.lkgV
MicroWorld-eScanGen:Variant.Babar.61480
ClamAVWin.Trojan.4430311-1
FireEyeGeneric.mg.bbd7ef2cfc7f71cd
CAT-QuickHealTrojan.Generic.30017
SkyhighBehavesLike.Win32.Rootkit.qh
ALYacGen:Variant.Babar.61480
Cylanceunsafe
ZillyaDownloader.Tobor.Win32.246
SangforSuspicious.Win32.Save.ins
AlibabaTrojanDownloader:Win32/Tobor.5dbad7e7
Cybereasonmalicious.710f8d
ArcabitTrojan.Babar.DF028
BitDefenderThetaAI:Packer.08AFE07E1F
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.PLR
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Babar.61480
NANO-AntivirusTrojan.Win32.Tobor.tnsbg
AvastWin32:Agent-ALIT [Drp]
TencentWin32.Trojan-Downloader.Oader.Aplw
EmsisoftGen:Variant.Babar.61480 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader5.43197
VIPREGen:Variant.Babar.61480
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Murlo.aot
WebrootW32.Malware.Gen
VaristW32/Trojan.EXZZ-8739
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Downloader]/Win32.Tobor
XcitiumTrojWare.Win32.TrojanDropper.Mudrop.H@1cukoj
MicrosoftTrojan:Win32/DSSDetection
ViRobotTrojan.Win32.A.Downloader.25600.GF
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Babar.61480
GoogleDetected
McAfeeGenericRXAA-FA!BBD7EF2CFC7F
MAXmalware (ai score=100)
VBA32TrojanDownloader.Tobor
MalwarebytesGeneric.Malware/Suspicious
PandaGeneric Malware
RisingWorm.Win32.ExeKiller.h (CLASSIC)
YandexTrojan.GenAsa!Qn2ScYNbGh8
IkarusTrojan-Downloader
MaxSecureTrojan.Malware.4595917.susgen
FortinetW32/Agent.UUAG!tr.dldr
AVGWin32:Agent-ALIT [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Babar.61480?

Babar.61480 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment