Malware

Babar.66541 (file analysis)

Malware Removal

The Babar.66541 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.66541 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Babar.66541?


File Info:

name: CCC22AC308D72C551EEF.mlw
path: /opt/CAPEv2/storage/binaries/008d36035e306b76b30744f895803c33162bf683366f87e1eba8405261e715e9
crc32: 626CC74F
md5: ccc22ac308d72c551eef13dd5b7b8571
sha1: 403eaf96f3bf26ff995884bfe091a609ffd809ca
sha256: 008d36035e306b76b30744f895803c33162bf683366f87e1eba8405261e715e9
sha512: f069aab31bbdf547ea30345bbff34bec5dabfb823b913c3aec0a9ab02ef4c0e8fa0524ac5d6021eac47fbe164e9ed0de8b89ce070fdaf87c07936da5a067c7d0
ssdeep: 12288:Db/slg6l6Ss3De+GNUTwu1ZkUf6j4Y6fiKNpELbG8mZa1hbEux+yAyFaiG4V4FQ1:Db/sTlODetqwu1ZP68DiBSa1hbnAyF/V
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T127E412203EE38D12D8F3CA7E1CD4AE398D1E74D712326A3EB62CD51CBA265425D6E11D
sha3_384: fc2af59056dae971e24f797162cedca6d96cbe5cda53465f213cc24d038e906a234868e56f5b7a9f6e14e35deb0d22f8
ep_bytes: 558bec81ecf40300005356576a205f33
timestamp: 2021-09-25 21:57:46

Version Info:

Comments: modejournalenim
CompanyName: Targu83
FileDescription: cupelled
FileVersion: 1.0.15
LegalCopyright: Sirrahs
LegalTrademarks: proboycot
ProductName: DEPRIMER
Translation: 0x0409 0x04b0

Babar.66541 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.GuLoader.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.66541
ALYacGen:Variant.Babar.66541
CylanceUnsafe
VIPREGen:Variant.Babar.66541
K7AntiVirusTrojan ( 00593d911 )
AlibabaTrojanDownloader:Win32/GuLoader.43bbcd6a
K7GWTrojan ( 00593d911 )
CyrenW32/Ninjector.CJ.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32NSIS/Injector.AUY
TrendMicro-HouseCallTROJ_GEN.R002C0PFE22
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Downloader.Win32.GuLoader.gen
BitDefenderGen:Variant.Babar.66541
NANO-AntivirusTrojan.Win32.GuLoader.jpgwrq
CynetMalicious (score: 99)
AvastNSIS:DropperX-gen [Drp]
TencentWin32.Trojan.FalseSign.Kzfl
Ad-AwareGen:Variant.Babar.66541
SophosMal/Generic-S
DrWebTrojan.Siggen18.1531
ZillyaDownloader.GuLoader.Win32.804
TrendMicroTROJ_GEN.R002C0PFE22
McAfee-GW-EditionRDN/Generic Downloader.x
FireEyeGen:Variant.Babar.66541
EmsisoftGen:Variant.Babar.66541 (B)
APEXMalicious
AviraTR/Injector.kmooj
Antiy-AVLTrojan/Generic.ASSuf.438B
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Babar.D103ED
ZoneAlarmHEUR:Trojan-Downloader.Win32.GuLoader.gen
GDataGen:Variant.Babar.66541
GoogleDetected
AhnLab-V3Malware/Gen.RL_Reputation.R365617
McAfeeRDN/Generic Downloader.x
MAXmalware (ai score=82)
MalwarebytesTrojan.GuLoader
FortinetW32/AUY.X!tr
AVGNSIS:DropperX-gen [Drp]
PandaTrj/Chgt.AB
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Babar.66541?

Babar.66541 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment