Malware

Barys.121514 removal

Malware Removal

The Barys.121514 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.121514 virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Barys.121514?


File Info:

name: 4A6C661E07042AA73197.mlw
path: /opt/CAPEv2/storage/binaries/4d1fd61f5202d7f7feabd2571ea100a30dbb1688f3d7ec78e416d04c451017f6
crc32: 9495DC9F
md5: 4a6c661e07042aa731971a83c59db53e
sha1: 7a329646daa1ea6b1d7ab721562c99c698b8364f
sha256: 4d1fd61f5202d7f7feabd2571ea100a30dbb1688f3d7ec78e416d04c451017f6
sha512: 0552e66a08fceb21296c825e4e17502eadbd859e8d15d380527f5964eae016a65e1a6474bb0aee258e72ff655fa32ef69197f082bc7d2b30a22f32f1e9075820
ssdeep: 3072:W/d4UYVULB+La7ijQqXWuVB3vUidQxSeBnULc5uszD9dDy6HaxFbhjChB:W/d4UYVULB+La7i5VB3simxFBnULc5ue
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16FF3C03DFA10611DEDE241793C553A3FBA481E7C0A446A66F7B1464EA0F2BE2B4E4707
sha3_384: d62d8eeb13ed9215dfa5177290ad77b00d534ec9fab7cc0ed73b9e23618ac928ce8e67b9c0f990af163083a57c929875
ep_bytes: 68d0244000e8eeffffff000000000000
timestamp: 2084-09-20 22:43:38

Version Info:

Translation: 0x0409 0x04b0

Barys.121514 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.121514
CAT-QuickHealWorm.Autorun.UI3
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeW32/Autorun.worm.gk
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 005ad8211 )
K7GWTrojan ( 005ad8211 )
BaiduWin32.Worm.Autorun.l
VirITWorm.Win32.VB.CE
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.EW
APEXMalicious
TrendMicro-HouseCallWORM_VB.SM
ClamAVWin.Worm.Barys-9800091-0
KasperskyWorm.Win32.VB.axb
BitDefenderGen:Variant.Barys.121514
NANO-AntivirusTrojan.Win32.VB.cnmtji
AvastWin32:AutoRun-BAE [Wrm]
TencentMalware.Win32.Gencirc.10b39f4e
EmsisoftGen:Variant.Barys.121514 (B)
F-SecureTrojan.TR/VB.fhdo
DrWebWin32.HLLW.Autoruner.64538
VIPREGen:Variant.Barys.121514
TrendMicroWORM_VB.SM
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.4a6c661e07042aa7
SophosMal/SillyFDC-D
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=80)
GoogleDetected
AviraTR/VB.fhdo
VaristW32/Autorun.HS.gen!Eldorado
Antiy-AVLWorm/Win32.VB
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Autorun.UI
XcitiumVirus.Win32.Virut.Ce@1fy3nv
ArcabitTrojan.Barys.D1DAAA
ViRobotWorm.Win32.A.VB.139776.X
ZoneAlarmWorm.Win32.VB.axb
GDataGen:Variant.Barys.121514
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Basun.R1388
Acronissuspicious
VBA32OScope.Trojan.VB.01580
ALYacGen:Variant.Barys.121514
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Autorun.JDK
RisingDropper.Win32.VB.fco (CLASSIC)
YandexTrojan.GenAsa!vgzaXTv/ojM
IkarusTrojan.VB
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenericKDZ.70291!tr
BitDefenderThetaAI:Packer.9024555B1F
AVGWin32:AutoRun-BAE [Wrm]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Autorun.2b6aea4e

How to remove Barys.121514?

Barys.121514 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment