Malware

Babar.99491 malicious file

Malware Removal

The Babar.99491 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.99491 virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Hungarian
  • Authenticode signature is invalid

How to determine Babar.99491?


File Info:

name: 5C1648E31340EC4E831E.mlw
path: /opt/CAPEv2/storage/binaries/a9e2479d95a8600b90d6fad6f7dc024741033c7e34f2ec09a1e9a54d5ad9653b
crc32: 7226DC9D
md5: 5c1648e31340ec4e831ea7b496280a74
sha1: 0ef133a7e3e87f3ec7c1b039d5ee4c43cb431f73
sha256: a9e2479d95a8600b90d6fad6f7dc024741033c7e34f2ec09a1e9a54d5ad9653b
sha512: 9daf7f1399d4f6df17563bc7027ada8b400f28efb30dee8f98624a45e3258324709bdd663adaf1cccddbf54278c9e37a599b3c2e443babcf5f844d4640f26c75
ssdeep: 12288:nv8h1OFOWnEkrTjk0f4Oyxequ4hdSoMQB8wLo2DrOEY9BCl8vG6qMeS4Tgges:vUOFxf4Aqu4hdSc98OrLYigeS4Uvs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10BE40243CB4783B2D2B571F543CF2F695F341AC41241194783AAAC2B69AB7B2706B79C
sha3_384: bc4862405912677d450ad8072f550384b8e56eb2339dd71169c7ae34ec4aafe770549607781dbfd4cd586ab4e5c17824
ep_bytes: 558bec81c4b8fcffff33d28b0d10e547
timestamp: 2008-05-25 03:45:55

Version Info:

CompanyName: BitDefender S.R.L.
FileDescription: BitDefender Antivirus Scanner
FileVersion: 13,0,21,1
InternalName: UIScanner
LegalCopyright: Copyright (C) 2010
OriginalFilename: uiscan.exe
ProductName: BitDefender 2010
ProductVersion: 13,0,18,344
Translation: 0x0409 0x04b0

Babar.99491 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.99491
FireEyeGeneric.mg.5c1648e31340ec4e
McAfeePWS-Zbot.gen.baq
CylanceUnsafe
VIPREGen:Variant.Babar.99491
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0026d7d11 )
K7GWTrojan ( 0026d7d11 )
Cybereasonmalicious.7e3e87
CyrenW32/FakeAlert.SU.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.OSQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Babar.99491
NANO-AntivirusRiskware.Win32.FlashApp.drnxm
AvastWin32:Mystic
Ad-AwareGen:Variant.Babar.99491
EmsisoftGen:Variant.Babar.99491 (B)
ZillyaTrojan.Kryptik.Win32.3749138
McAfee-GW-EditionPWS-Zbot.gen.baq
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/FakeAV-MR
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Babar.99491
JiangminTrojan.Generic.ebdjt
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan[Rogue]/Win32.Winwebsec
ArcabitTrojan.Babar.D184A3
MicrosoftTrojan:Win32/Bulta!rfn
GoogleDetected
AhnLab-V3Trojan/Win32.FakeAV.R5355
VBA32Trojan.ExpProc.014
ALYacGen:Variant.Babar.99491
MAXmalware (ai score=80)
MalwarebytesMalware.Heuristic.1006
RisingRansom.Timer!8.30B6 (TFE:2:ik50vMKc7j)
IkarusTrojan.Win32.Yakes
MaxSecureTrojan.Yakes.dwnc
FortinetW32/BrowHost.KP!tr
BitDefenderThetaGen:NN.ZexaF.34682.Qu2@aCd@WzdO
AVGWin32:Mystic
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Babar.99491?

Babar.99491 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment