Malware

How to remove “Babar.97817”?

Malware Removal

The Babar.97817 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.97817 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Anomalous binary characteristics

How to determine Babar.97817?


File Info:

name: 876CC8C68140F50AFCD6.mlw
path: /opt/CAPEv2/storage/binaries/46a4b8706827eb7552016529bcf578a2273ff47ab2c5123199ad4a72e5d47d7f
crc32: AEECB2ED
md5: 876cc8c68140f50afcd65b2c14520a78
sha1: 9de1d15079330e0d154cbe13ec811f5fb815aa12
sha256: 46a4b8706827eb7552016529bcf578a2273ff47ab2c5123199ad4a72e5d47d7f
sha512: b9896c9224665dd215b1779238a91de9d032ff287f3fbf18841380f20a59a475fb8c2907f7fab66893d2f7b3ab4271d2cc99ae364e91027cd87e2b11b6143a03
ssdeep: 24576:u9IrqYcYc0BbQzGMigl8XBfkJIZO5TuzmSxh0LMpNLISkzVZy3NAmRl3RuQ5531I:yIhKJIJmjLMpNual3W
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1A9C509039ACB1E75DDC23BB4618B533BA734ED30CA2A9B7FF609C53599532C4681A742
sha3_384: b4fedbfa24cea967beaf8d2c23bad4bfeaafea61970d8961dbd0580ff35cd91b8c584bf4a5136d2163d9b1ffa391911d
ep_bytes: 83ec0cc705b823510000000000e80e4c
timestamp: 2022-08-28 22:41:44

Version Info:

0: [No Data]

Babar.97817 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.97817
FireEyeGen:Variant.Babar.97817
CAT-QuickHealTrojan.GenericPMF.S28392069
MalwarebytesTrojan.FakeSig
K7AntiVirusTrojan ( 005969171 )
K7GWTrojan ( 005969171 )
Cybereasonmalicious.079330
CyrenW32/Trojan.HLPX-5019
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HQDK
Paloaltogeneric.ml
KasperskyVHO:Trojan-Spy.Win32.Stealer.cmiw
BitDefenderGen:Variant.Babar.97817
AvastFileRepMalware [Trj]
Ad-AwareGen:Variant.Babar.97817
McAfee-GW-EditionGenericRXTZ-XN!876CC8C68140
SentinelOneStatic AI – Suspicious PE
GoogleDetected
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.HS3PEA
CynetMalicious (score: 100)
VBA32Trojan.MSIL.InfoStealer.gen.U
CylanceUnsafe
RisingTrojan.Kryptik!8.8 (TFE:5:qFgFsCC2vGK)
IkarusTrojan.Win32.RedlineStealer
MaxSecureTrojan.WIN32.Zenpak.gen_223205
BitDefenderThetaGen:NN.ZexaCO.34606.z!Z@amY!pRe
AVGFileRepMalware [Trj]

How to remove Babar.97817?

Babar.97817 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment