Malware

Barys.1424 removal guide

Malware Removal

The Barys.1424 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.1424 virus can do?

  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Anomalous binary characteristics

How to determine Barys.1424?


File Info:

crc32: FA008B3B
md5: c9c233eeba8f1dd5f4ff63df4105eaa0
name: C9C233EEBA8F1DD5F4FF63DF4105EAA0.mlw
sha1: 339255486c1ced7e79ceb600e0b107590447a54f
sha256: cbba06459b171b01b3c309ddbef4de61c400071bce9e3e4cf241e1dc6e29462e
sha512: 46c8804e2af3c2c695e96c3225a066080a488151e524008e45d9cbf84509c9e052c7e36560d0a90f1deaaac1f1f2e0c00eb279242a6bf0222aceafe187d2b377
ssdeep: 768:xu4SyXelhD1XgSDqy+52/EPK6+Sv7az1UgGfirwN/Gu1:xRSyXMh5892oCSv7az1UxiCG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 360.cn
InternalName: 360Safe.exe
FileVersion: 9, 8, 0, 1108
CompanyName: 360.cn
ProductName: 360x5b89x5168x536bx58eb x4e3bx7a0bx5e8fx6a21x5757
ProductVersion: 9, 8, 0, 1108
FileDescription: 360x5b89x5168x536bx58eb x4e3bx7a0bx5e8fx6a21x5757
OriginalFilename: 360Safe.exe
Translation: 0x0804 0x04b0

Barys.1424 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0054d1101 )
Elasticmalicious (high confidence)
DrWebTrojan.DnsAmp.24
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Nitol.A
ALYacGen:Variant.Barys.1424
CylanceUnsafe
SangforWin.Trojan.Nitol-6335025-0
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/PornoBlocker.fd7a2f34
K7GWTrojan ( 0054d1101 )
Cybereasonmalicious.eba8f1
BaiduWin32.Trojan.ServStart.a
CyrenW32/S-e0ea738f!Eldorado
SymantecBackdoor.Nitol
ESET-NOD32a variant of Win32/ServStart.D
APEXMalicious
AvastWin32:GenMalicious-BKJ [Trj]
ClamAVWin.Worm.Agent-5819819-0
KasperskyTrojan-Ransom.Win32.PornoBlocker.ejwo
BitDefenderGen:Variant.Barys.1424
NANO-AntivirusTrojan.Win32.Buzus.rkatz
ViRobotBackdoor.Win32.ServStart.Gen.A
MicroWorld-eScanGen:Variant.Barys.1424
TencentRootkit.Win32.Lapka.a
Ad-AwareGen:Variant.Barys.1424
SophosML/PE-A + Troj/Nitol-AR
ComodoTrojWare.Win32.ServStart.E@555zmt
BitDefenderThetaAI:Packer.F5BAFB4A1F
VIPRETrojan.Win32.Zegost.lt (v)
TrendMicroTROJ_NITOL.SMN1
McAfee-GW-EditionBehavesLike.Win32.Generic.ph
FireEyeGeneric.mg.c9c233eeba8f1dd5
EmsisoftGen:Variant.Barys.1424 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Dinwod.ke
AviraWORM/Rbot.Gen
eGambitTrojan.Generic
MicrosoftDDoS:Win32/Nitol.B
ZoneAlarmHEUR:Trojan-DDoS.Win32.Nitol.gen
GDataWin32.Worm.ServStart.B
AhnLab-V3Trojan/Win32.Rbot.R92130
Acronissuspicious
McAfeeDoS-FAK!C9C233EEBA8F
MAXmalware (ai score=89)
VBA32BScope.Trojan.DDoS.Nitol
MalwarebytesNitol.HackTool.DDoS.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_NITOL.SMN1
RisingTrojan.DDOS!1.AF40 (CLOUD)
YandexTrojan.DL.Agent!sdhyuJQ1PlM
IkarusWorm.Win32.ServStart
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/ServStart.EQ!tr
AVGWin32:GenMalicious-BKJ [Trj]
Paloaltogeneric.ml
Qihoo-360HEUR/QVM41.1.6A6F.Malware.Gen

How to remove Barys.1424?

Barys.1424 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment