Malware

Babar.73591 (file analysis)

Malware Removal

The Babar.73591 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.73591 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Babar.73591?


File Info:

name: AD7973CEBFABD0E48264.mlw
path: /opt/CAPEv2/storage/binaries/58e97d31ec102a9684d724049c4ddfc4bac4df6876b06ae976fb9f1a39b4ede4
crc32: E577CC15
md5: ad7973cebfabd0e4826444c2053eb561
sha1: 4466d37ae3f41c0b17c58e10a52137eee2de1b18
sha256: 58e97d31ec102a9684d724049c4ddfc4bac4df6876b06ae976fb9f1a39b4ede4
sha512: a654b6c95168fb3f6844b9f79cee6cabe2d3205f93a4cd28be0dfa534a1c1f7d6270b55121e61729c7fcf4967fed6edd9a352f96e48fe6fa10fc02de5260902c
ssdeep: 24576:n/bpmmY0Vm++Ylg42NV6yic11B9RkKQukQ4i+gxsX+J:n/VbVVm++YlN22cDMFuP4i5eX+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11535E068A31530CCD42FEFF83DDDB9D48D5436533E0795D25CEBD88902ACBAA8368946
sha3_384: b8cbba63fe4fc32e1ff44e53e3571a500541f54b6e8037b8e30e50679140372485b0fc46077c1869e889fbc8e26e9d70
ep_bytes: 5150528d0d18000000648b0101c801c8
timestamp: 2004-11-07 18:52:04

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Self-Extracting Cabinet
FileVersion: 6.1.0022.0 (SRV03_QFE.031113-0918)
InternalName: SFXCAB.EXE
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: SFXCAB.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.0022.0
Translation: 0x0409 0x04b0

Babar.73591 also known as:

DrWebWin32.Expiro.150
MicroWorld-eScanGen:Variant.Babar.73591
FireEyeGeneric.mg.ad7973cebfabd0e4
ALYacGen:Variant.Babar.73591
CylanceUnsafe
VIPREGen:Variant.Babar.73591
K7AntiVirusVirus ( 0058dc741 )
K7GWVirus ( 0058dc741 )
CrowdStrikewin/malicious_confidence_70% (W)
VirITWin32.Expiro.CV
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.CP
APEXMalicious
ClamAVWin.Dropper.Expiro-9923115-0
KasperskyVirus.Win32.Expiro.ns
BitDefenderGen:Variant.Babar.73591
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Xpirat-C [Inf]
Ad-AwareGen:Variant.Babar.73591
EmsisoftGen:Variant.Babar.73591 (B)
McAfee-GW-EditionTrojan-FUNU!AD7973CEBFAB
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.PSW.Stealer.abj
GoogleDetected
AviraW32/Infector.Gen8
Antiy-AVLTrojan/Generic.ASVirus.315
MicrosoftTrojan:Win32/Raccoon.EC!MTB
ArcabitTrojan.Babar.D11F77
GDataGen:Variant.Babar.73591
CynetMalicious (score: 100)
McAfeeTrojan-FUNU!AD7973CEBFAB
MAXmalware (ai score=82)
VBA32BScope.Trojan.Wacatac
IkarusVirus.Win32.Expiro
FortinetW32/Expiro.NDG
AVGWin32:Xpirat-C [Inf]
Cybereasonmalicious.ae3f41

How to remove Babar.73591?

Babar.73591 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment