Malware

Barys.193426 malicious file

Malware Removal

The Barys.193426 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.193426 virus can do?

  • Sample contains Overlay data
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Barys.193426?


File Info:

name: B9589B20E9C007487266.mlw
path: /opt/CAPEv2/storage/binaries/11f59b4c42deda79f1f09d7eb201335fe195e8accfaaa303b358ca28d7ac3f63
crc32: 9CDD0DA7
md5: b9589b20e9c0074872664c0254612c3a
sha1: aa4bb0b2742ebc42fdc947895340d3b9ce3e9557
sha256: 11f59b4c42deda79f1f09d7eb201335fe195e8accfaaa303b358ca28d7ac3f63
sha512: dee8ba7c55e95470ebbd64d18f1f679473264918935dcf6e643f0daff87faded39ab52e8a551425db82f690a64325cdbe9f8858aefacef6488e1bd8ab00a471d
ssdeep: 6144:Q66v1UNIPcmmmRm4EG76adSNc/B9XgGJ2FxQ:HwEmREGO8oc/B9QLQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T159F4AE137BE0C077D642443189A65FB6FFFBE2340E6685875368CE1CDF319A1C52A62A
sha3_384: ab2e122c7f958457cf00534835b9b5f56a006513af909403e580b1e087d113944cecd6312a828def7aafc3a0aaf024c8
ep_bytes: 558bec6aff68f0704000682034400064
timestamp: 2012-01-14 14:09:57

Version Info:

Comments:
CompanyName: Shenzhen QVOD Technology Co.,Ltd
FileDescription: QvodInstall Module
FileVersion: 4, 0, 4, 6
InternalName: QvodInstall.exe
LegalCopyright: Copyright(C) 2006-2012 QVOD
LegalTrademarks:
OriginalFilename: QvodInstall.exe
PrivateBuild:
ProductName: QvodInstall Module
ProductVersion: 4, 0, 4, 6
SpecialBuild:
Translation: 0x0409 0x0000

Barys.193426 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Rimod.b!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.193426
FireEyeGeneric.mg.b9589b20e9c00748
CAT-QuickHealTrojan.IgenericRI.S27872755
SkyhighBehavesLike.Win32.Dropper.bz
McAfeeGenDownloader.oj
Cylanceunsafe
VIPREGen:Variant.Barys.193426
SangforDropper.Win32.Agent.Vuf8
K7AntiVirusTrojan ( 005203381 )
AlibabaTrojanDropper:Win32/Rimod.2554df15
K7GWTrojan ( 005203381 )
Cybereasonmalicious.0e9c00
BitDefenderThetaGen:NN.ZexaF.36802.pqW@aW9HLrab
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDropper.Agent.PRE
APEXMalicious
TrendMicro-HouseCallTSPY_DOWNLOADER_BL132B39.TOMC
ClamAVWin.Dropper.Genericrxeo-9849932-0
KasperskyTrojan-Dropper.Win32.Agent.bjvcpv
BitDefenderGen:Variant.Barys.193426
NANO-AntivirusTrojan.Win32.Rimod.crgjki
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Qvod.kal
TACHYONTrojan-Downloader/W32.Qvod.727680
EmsisoftGen:Variant.Barys.193426 (B)
BaiduWin32.Trojan-Dropper.Agent.s
F-SecureTrojan.TR/Rimod.AJ.1
DrWebTrojan.DownLoader25.31573
ZillyaDropper.Agent.Win32.114248
TrendMicroTSPY_DOWNLOADER_BL132B39.TOMC
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.Agent
JiangminTrojan/Generic.ahrto
GoogleDetected
AviraTR/Rimod.AJ.1
VaristW32/Rimod.A.gen!Eldorado
Antiy-AVLTrojan/Win32.Rimod
KingsoftWin32.HeurC.KVM003.a
MicrosoftTrojanDownloader:Win32/Troxen!rts
XcitiumTrojWare.Win32.Rimod.aj@4tvs05
ArcabitTrojan.Barys.D2F392
ViRobotTrojan.Win32.Z.Qvod.727680.L
ZoneAlarmTrojan-Dropper.Win32.Agent.bjvcpv
GDataGen:Variant.Barys.193426
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Downloader.R20670
VBA32TrojanDownloader.Qvod
ALYacGen:Variant.Barys.193426
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingTrojan.DL.Win32.AVPlayer.a (CLASSIC)
YandexTrojan.GenAsa!rD/75XOjNFg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qvod.PRE!tr.dldr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan[dropper]:Win/Barys

How to remove Barys.193426?

Barys.193426 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment