Adware

Adware.ICloader.Barys.7 malicious file

Malware Removal

The Adware.ICloader.Barys.7 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.ICloader.Barys.7 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Queries information on disks, possibly for anti-virtualization
  • Detects the presence of Wine emulator via registry key

How to determine Adware.ICloader.Barys.7?


File Info:

crc32: F1980D3B
md5: 323d166d6333fa0413f87131b857d8f5
name: 323D166D6333FA0413F87131B857D8F5.mlw
sha1: f5b4ea825031e0687924f1b88a85da800bdb16cf
sha256: 1a194f3c40f96c39329a97bbaf475340561e5b8e6fae641e98bf96f3e3001578
sha512: e9912da83eadf61908eba1f667da7cb6b70b1904ff3679eccf15a4a5115de347322d8f4627a8610fb76b6ea3602315b961af7543062a5b80ca4f55fe8cf16d3f
ssdeep: 49152:APTG91LuWj1dchPGct4yuEeVhGAfC+lR5:APTG91vjrKPGctAVfjf5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2005-2017 iform-zero Ltd
InternalName: ccleaner
FileVersion: 5, 32, 00, 6129
CompanyName: iform-zero Ltd
Comments: CCleaner
ProductName: CCleaner
ProductVersion: 5, 32, 00, 6129
FileDescription: CCleaner
OriginalFilename: ccleaner.exe
Translation: 0x0409 0x04b0

Adware.ICloader.Barys.7 also known as:

K7AntiVirusTrojan ( 005241d51 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.2647
CynetMalicious (score: 100)
CAT-QuickHealSwBundler.ICLoader.YB5
ALYacGen:Variant.Adware.ICloader.Barys.7
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3096666
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:Win32/Katusha.d75b6ed5
K7GWTrojan ( 005241d51 )
Cybereasonmalicious.d6333f
CyrenW32/S-af01ab11!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GCAT
APEXMalicious
AvastWin32:DangerousSig [Trj]
ClamAVWin.Packed.Icloader-6952325-0
KasperskyUDS:Packed.Win32.Katusha.gen
BitDefenderGen:Variant.Adware.ICloader.Barys.7
NANO-AntivirusTrojan.Win32.Ekstak.exhauv
MicroWorld-eScanGen:Variant.Adware.ICloader.Barys.7
Ad-AwareGen:Variant.Adware.ICloader.Barys.7
SophosMal/Generic-S
ComodoMalware@#3stuv9kepzkv7
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPacked-OF!323D166D6333
FireEyeGeneric.mg.323d166d6333fa04
EmsisoftApplication.AdLoad (A)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.243B862
MicrosoftPUADlManager:Win32/InstallCube
ZoneAlarmHEUR:Packed.Win32.Katusha.gen
GDataGen:Variant.Adware.ICloader.Barys.7
AhnLab-V3PUP/Win32.ICLoader.R218959
Acronissuspicious
McAfeePacked-OF!323D166D6333
MAXmalware (ai score=100)
VBA32BScope.Trojan.InstallCube
MalwarebytesAdware.FileTour
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AFA6 (CLASSIC)
YandexTrojan.GenAsa!e6/gh/6LzgA
IkarusPUA.Win32.ICLoader
MaxSecurePacked.Packed.WIN32.Katusha.gen_211988
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml

How to remove Adware.ICloader.Barys.7?

Adware.ICloader.Barys.7 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment