Malware

Babar.97991 removal

Malware Removal

The Babar.97991 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.97991 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Babar.97991?


File Info:

name: D76CC61E41AD580A8539.mlw
path: /opt/CAPEv2/storage/binaries/ce6f652027fd7e1d34444f032de1ac893f098719a5dd90a5d75fe994183d2ea8
crc32: 42DCFE58
md5: d76cc61e41ad580a853982dbd1639943
sha1: 341eaa6cb5294ba7b0f7d0b0e21a2c5c33341e92
sha256: ce6f652027fd7e1d34444f032de1ac893f098719a5dd90a5d75fe994183d2ea8
sha512: 258bf43209e56c3ec84ae409f59520b2f6f67b7a10fde6592a359c0de1e58ce1e5e8cb0bb8691d4c2052f81275732c673ce91d2f29b841be839937026dff2f96
ssdeep: 49152:yLItNupichxm9cpKqILl8f1T5KqILl8fWNgyc:XWpichxm9Y/ILl8fP/ILl8f4g
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12FE59E43BA82C0F5D60D163008AA7B3A9A795F550B25CFC3E764EE7DAD32190D63724E
sha3_384: a2cb9e59f6ba33aaf215b7e871a151168ae6e2d5b5e0abf65c2a7df96736da0d9116673b85a9337f38734c4ac9d203b5
ep_bytes: 558bec6aff6848826a006864e74d0064
timestamp: 2022-08-05 08:26:43

Version Info:

FileVersion: 1.0.0.0
FileDescription: VIP用户定制,定制QQ:3175426804.
ProductName: 火线精英定制款辅助
ProductVersion: 1.0.0.0
CompanyName: Z
LegalCopyright: 此科技为Z制作(QQ:3175426804)
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Babar.97991 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Multi.Generic.mpTZ
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.97991
CAT-QuickHealTrojan.Generic.2919
McAfeeArtemis!D76CC61E41AD
CylanceUnsafe
ZillyaTool.HackTool.Win32.4139
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.cb5294
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/RiskWare.HackTool.Agent.AO
APEXMalicious
ClamAVWin.Malware.Trojanx-9951053-0
KasperskyUDS:Virus.Win32.Nimnul.a
BitDefenderGen:Variant.Babar.97991
AvastWin32:Evo-gen [Trj]
TencentWin32.Virus.Ramnit.Ncnw
Ad-AwareGen:Variant.Babar.97991
EmsisoftGen:Variant.Babar.97991 (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
F-SecureMalware.W32/Ramnit.C
DrWebWin32.Rmnet.8
VIPREGen:Variant.Babar.97991
TrendMicroTROJ_GEN.R002C0WHV22
McAfee-GW-EditionArtemis!Virus
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.d76cc61e41ad580a
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.10248TU
JiangminTrojanDropper.Binder.avg
GoogleDetected
AviraW32/Ramnit.C
Antiy-AVLTrojan/Win32.FlyStudio.a
ArcabitTrojan.Babar.D17EC7
ZoneAlarmUDS:Virus.Win32.Nimnul.a
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Trojan.Rootkit
ALYacGen:Variant.Babar.97991
MAXmalware (ai score=84)
MalwarebytesRamnit.Virus.FileInfector.DDS
TrendMicro-HouseCallTROJ_GEN.R002C0WHV22
RisingTrojan.Generic@AI.98 (RDML:71FVJqqYSjacr31nyE/jJQ)
IkarusTrojan.Win32.MBRlock
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.65CA!tr
BitDefenderThetaGen:NN.ZexaF.34796.4s0@aarIEUaH
AVGWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Babar.97991?

Babar.97991 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment