Malware

Babar.97025 removal guide

Malware Removal

The Babar.97025 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.97025 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Babar.97025?


File Info:

name: 51F5AC6AFC04A0306C4F.mlw
path: /opt/CAPEv2/storage/binaries/53ef96e0211b26af0173f56be065b05ca3d4300944f5855d65f3eef5289584fb
crc32: 39DB5102
md5: 51f5ac6afc04a0306c4fac41fcf4dfcc
sha1: b53012154dcd73e2943c5344eca50b41314a8411
sha256: 53ef96e0211b26af0173f56be065b05ca3d4300944f5855d65f3eef5289584fb
sha512: 91ef81edb45a5ba71d5cfcceba5a4734da8298d7e33ebd6763a6b87784e78f1fee32542c36e0cc5fd7a2b8e0d2717ff3d1b59a8744fb7eb5441f75bd621cbff9
ssdeep: 12288:0UFr6V4t30Ea7ghK7KtfRoyujENbesD5wKUk:0ZghKsfS+bjD4k
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19FF56E313BA38473DDF230BA06ED7420156DB4B01725DAC753D80AEED6746D06B3AA9B
sha3_384: bd82d0df543ca4637969b3f5701db40ebb0f24e51a518d99fa48e5678b0388b9aa96e3b7fd8fb13a5bce1745db0e36a0
ep_bytes: e96aac0000e99ed60100e962da0000e9
timestamp: 2022-08-24 18:07:04

Version Info:

0: [No Data]

Babar.97025 also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanGen:Variant.Babar.97025
FireEyeGeneric.mg.51f5ac6afc04a030
ALYacGen:Variant.Babar.97025
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.FZCA
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Babar.97025
AvastPWSX-gen [Trj]
Ad-AwareGen:Variant.Babar.97025
EmsisoftGen:Variant.Babar.97025 (B)
DrWebTrojan.PWS.Steam.28157
VIPREGen:Variant.Babar.97025
SophosGeneric ML PUA (PUA)
GDataGen:Variant.Babar.97025
ArcabitTrojan.Babar.D17B01
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Generic.C5200570
Acronissuspicious
MAXmalware (ai score=81)
RisingBackdoor.Mokes!8.619 (TFE:dGZlOgWXRaUOXsSWJw)
SentinelOneStatic AI – Malicious PE
BitDefenderThetaGen:NN.ZexaF.34606.BFZ@a0J@!Iji
AVGPWSX-gen [Trj]

How to remove Babar.97025?

Babar.97025 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment