Malware

Babar.83468 (B) removal guide

Malware Removal

The Babar.83468 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.83468 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Likely virus infection of existing system binary
  • Deletes executed files from disk

How to determine Babar.83468 (B)?


File Info:

name: 2D9BDB0986D2F8BA8DB6.mlw
path: /opt/CAPEv2/storage/binaries/70616fd386b8a5de7426f5fd44d54920a462b1c4567d04294cdd576026b01b71
crc32: 290653C9
md5: 2d9bdb0986d2f8ba8db6635f0447cfd4
sha1: 996e92dcbc07cb98e8cb8c2c003196adae98d352
sha256: 70616fd386b8a5de7426f5fd44d54920a462b1c4567d04294cdd576026b01b71
sha512: b1d4d83cf776f546b9bac422533502bb723072604bf2835bce414de7c199404907b04e7b64ca3f3aa28de8150173b3ac81157e990c531e2bba5364b9ca505594
ssdeep: 24576:SfOy6l+mTNx3ko/iulP+Z57eVrWqgk1QB0HVyGH4yLP8PFG0MjVpl0zJEHbE8g7q:SGFxr3M4PC57eVyqV9cGH94FXMadEXN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BB553318C6A8B03AD425D7B01FA75686673FBE51323E9424329F058E1F2BB82DD5B353
sha3_384: 1f469d8527a0d1b8427324cf59a3b739f31d9c8f49350c3ca67f8f9f156220cd8fd9fc8309126088561a627125150179
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Nvidl Labs, Inc.
FileDescription: Virtual Disk Manager
FileVersion: 1.0.0.9
LegalCopyright:
Translation: 0x0409 0x04e4

Babar.83468 (B) also known as:

MicroWorld-eScanGen:Variant.Babar.83468
FireEyeGen:Variant.Babar.83468
McAfeeArtemis!2D9BDB0986D2
VIPREGen:Variant.Babar.83468
SangforTrojan.Win32.GCleaner.gen
K7AntiVirusTrojan ( 005722fe1 )
K7GWTrojan ( 005722fe1 )
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
KasperskyHEUR:Trojan-Downloader.Win32.GCleaner.gen
BitDefenderGen:Variant.Babar.83468
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Babar.83468
EmsisoftGen:Variant.Babar.83468 (B)
F-SecureTrojan.TR/Drop.Agent.vtrjg
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.Agent
GDataWin32.Malware.GleaMal.T4UKV1
JiangminTrojan.Ekstak.bvsc
AviraTR/Drop.Agent.vtrjg
ArcabitTrojan.Babar.D1460C
ZoneAlarmHEUR:Trojan-Downloader.Win32.GCleaner.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
ALYacGen:Variant.Babar.83468
MAXmalware (ai score=85)
APEXMalicious
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.SLC!tr
AVGWin32:Trojan-gen

How to remove Babar.83468 (B)?

Babar.83468 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment