Malware

Barys.127859 removal instruction

Malware Removal

The Barys.127859 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.127859 virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • CAPE detected the Macoute malware family

How to determine Barys.127859?


File Info:

name: A32CB378239EAB8B0C99.mlw
path: /opt/CAPEv2/storage/binaries/b85b2a1a70aa7b92002a33bea46da07e4c289d5d7fc6db8625e15225f2376681
crc32: 2C84F817
md5: a32cb378239eab8b0c99fe9dc1c31d69
sha1: 544e2633d261ebc58bbc7d4f372e51be16d83697
sha256: b85b2a1a70aa7b92002a33bea46da07e4c289d5d7fc6db8625e15225f2376681
sha512: d3e44b88e25d23a8186368e3046e9e3d0a2ae694dde12baa0f87c6ed60f91b8bfce993f9cc423cae7011661ba46c4415444f3416cb6b94d9f995ee4139f1dec1
ssdeep: 6144:nafsiuvAJ+tCtCw6cyERSiytj71cW+t4jKS6vHvEJ:ECvAJ+6n6ctRt636WvjO3E
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T154159E81EBD340F2D8970FB15067A37FAB325E0D541CDD9AD3947E59AC33223AA29784
sha3_384: 4fbe016a8b434b8e32ece4e2034dd482d4715417a6db60626fa1574721516aae7cc0631c7fea46389e5624fc3cb9e4ba
ep_bytes: 00000000000000000000000000000000
timestamp: 2004-12-29 06:51:45

Version Info:

0: [No Data]

Barys.127859 also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Barys.o!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.127859
ClamAVWin.Malware.Zusy-9889629-0
FireEyeGeneric.mg.a32cb378239eab8b
CAT-QuickHealTrojan.GenericPMF.S2958776
SkyhighBehavesLike.Win32.Generic.cz
McAfeeArtemis!A32CB378239E
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.Agent.Win32.52936
SangforSuspicious.Win32.Save.a
AlibabaWorm:Win32/Macoute.17e8cd79
CrowdStrikewin/malicious_confidence_90% (W)
ArcabitTrojan.Barys.D1F373
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.NYA
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Barys.127859
AvastWin32:Dropper-GUP [Drp]
SophosMal/Generic-S
BaiduWin32.Worm.Agent.bv
F-SecureTrojan.TR/Patched.Ren.Gen
VIPREGen:Variant.Barys.127859
TrendMicroWORM_MACOUTE.SMJ1
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Barys.127859 (B)
IkarusWorm.Win32.Macoute
WebrootW32.Trojan.Gen
AviraTR/Patched.Ren.Gen
Antiy-AVLWorm/Win32.Macoute
Kingsoftmalware.kb.a.994
MicrosoftWorm:Win32/Macoute.A
GDataGen:Variant.Barys.127859
VaristW32/S-2a9976b8!Eldorado
Acronissuspicious
ALYacGen:Variant.Barys.127859
MAXmalware (ai score=88)
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallWORM_MACOUTE.SMJ1
RisingWorm.Macoute!1.A746 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.NYA!worm
AVGWin32:Dropper-GUP [Drp]
Cybereasonmalicious.3d261e
DeepInstinctMALICIOUS

How to remove Barys.127859?

Barys.127859 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment