Malware

Ser.Babar.663 removal tips

Malware Removal

The Ser.Babar.663 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Babar.663 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Uses Windows utilities to enumerate running processes
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Detects BullGuard Antivirus through the presence of a library
  • Created a process from a suspicious location
  • Detects the presence of Windows Defender AV emulator via files
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempted to write directly to a physical drive
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ser.Babar.663?


File Info:

name: B940DE0C1D97D4E70AB2.mlw
path: /opt/CAPEv2/storage/binaries/5c1dfcf04363a87800dafb49fb05984766556db62c852c4ced7b786f5e12df5a
crc32: BAE5DA5F
md5: b940de0c1d97d4e70ab2a7b9bcce3c4c
sha1: 5803c014221811ee5c30bcbf7f67ffda1af7f376
sha256: 5c1dfcf04363a87800dafb49fb05984766556db62c852c4ced7b786f5e12df5a
sha512: 6c48d90ea28be49d06aef7fc15c52dcf8312a8530b9eead239cd16d17691aada4a34eff7fcf59e6df142f1a3ce1c611cfb4fc19896bd3400cd584414bcd4f665
ssdeep: 12288:dicN4nHUj2SGQnhYBRtpRWWUyr/Lh8rgV/KPXwzkQoTyJCwkWCfd0XswA:bN4nHLxQnhYfRVUI/tl4PXwzoTy8b0X4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B7E41202B9E58176E1E627314E85BF3847FEE7B20471446B67AC020A9EA5BC2DF1D317
sha3_384: d6a53870a697155b356126f8a3cb05e5a169c27e396eac98ceffd1db676ca0128ac7788ce3b0b294b160e6e318058f9a
ep_bytes: e8a3020000e957fdffffccff25846241
timestamp: 2022-02-10 22:42:48

Version Info:

CompanyName: Oleg N. Scherbakov
FileDescription: 7z Setup SFX (x86)
FileVersion: 1.7.1.3901
InternalName: 7ZSfxMod
LegalCopyright: Copyright © 2005-2016 Oleg N. Scherbakov
OriginalFilename: 7ZSfxMod_x86.exe
PrivateBuild: October 31, 2017
ProductName: 7-Zip SFX
ProductVersion: 1.7.1.3901
Translation: 0x0000 0x04b0

Ser.Babar.663 also known as:

LionicTrojan.Multi.Generic.4!c
MicroWorld-eScanGen:Variant.Ser.Babar.663
FireEyeGen:Variant.Ser.Babar.663
ALYacGen:Variant.Ser.Babar.663
CylanceUnsafe
SangforRiskware.Win32.Agent.ky
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
ArcabitTrojan.Ser.Babar.663
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.7Zip.Z
TrendMicro-HouseCallTROJ_GEN.R002C0PBF22
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Agent.myuhdf
BitDefenderGen:Variant.Ser.Babar.663
Ad-AwareGen:Variant.Ser.Babar.663
EmsisoftGen:Variant.Ser.Babar.663 (B)
DrWebTrojan.MulDrop19.30667
TrendMicroTROJ_GEN.R002C0PBF22
McAfee-GW-EditionRDN/Generic Dropper
SophosGeneric ML PUA (PUA)
APEXMalicious
JiangminBackdoor.Agent.lee
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Script/Phonzy.C!ml
ZoneAlarmBackdoor.Win32.Agent.myuhdf
GDataGen:Variant.Ser.Babar.663
AhnLab-V3Dropper/Win.BackDoor.C4968566
McAfeeRDN/Generic Dropper
MAXmalware (ai score=82)
VBA32Trojan.Wacatac
PandaTrj/CI.A
TencentWin32.Backdoor.Agent.Pfiu
IkarusTrojan.Win32.7zip
FortinetW32/PossibleThreat
WebrootW32.Malware.Gen
AVGWin32:DropperX-gen [Drp]
AvastWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Ser.Babar.663?

Ser.Babar.663 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment