Malware

Barys.309819 removal

Malware Removal

The Barys.309819 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.309819 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Barys.309819?


File Info:

name: F0251DE51BCA319EA601.mlw
path: /opt/CAPEv2/storage/binaries/a869e4e576fe33bdeaa0eae99b074e0e114eec7952db2dabf500a323f3bd849c
crc32: AFBA096E
md5: f0251de51bca319ea6015b006e500f5e
sha1: eaf227b94cdcefd9c1d68ec6bd078e17b4688198
sha256: a869e4e576fe33bdeaa0eae99b074e0e114eec7952db2dabf500a323f3bd849c
sha512: d9ee37102fa4774f04cd7b4421995d09ba47d4905bd78241f0956338f4e9ed3496a1637c5356fab89af85b96c221138d05d8831a74b6cfce246436c98e51f626
ssdeep: 196608:91OXHstmB4IUhj7PIk43YH4rPM+ve8cAi3oXj3r+T8yCl:3OXsA7Uhj7PIVCiXe8chYXjy87
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1377633217892D17FDA110433AE302BE5C1C2D6E74E31863773680A6F49BE59CB1B9DB9
sha3_384: bbf4f1c097287cd8dc0cec5595d234381e79b55b15f18ca2a30c3fd4882ec75345beaa7ef2c9cbe1b9c715f27728f4c1
ep_bytes: 558bec6aff68e0b94100682c4a410064
timestamp: 2010-11-18 16:27:35

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Setup SFX
FileVersion: 9.20
InternalName: 7zS.sfx
LegalCopyright: Copyright (c) 1999-2010 Igor Pavlov
OriginalFilename: 7zS.sfx.exe
ProductName: 7-Zip
ProductVersion: 9.20
Translation: 0x0409 0x04b0

Barys.309819 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.309819
FireEyeGen:Variant.Barys.309819
ALYacGen:Variant.Barys.309819
Cylanceunsafe
VIPREGen:Variant.Barys.309819
SangforAdware.Win32.Neoreklami.V6y4
AlibabaAdWare:Win32/Neoreklami.be643e90
CrowdStrikewin/grayware_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.36348.@xW@a8RXiIj
CyrenW32/Kryptik.IXP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Neoreklami.MF
APEXMalicious
KasperskyUDS:Trojan-Dropper.Win32.Agent.pef
BitDefenderGen:Variant.Barys.309819
AvastWin32:Adware-gen [Adw]
TencentWin32.Trojan-Dropper.Agent.Kflw
EmsisoftGen:Variant.Barys.309819 (B)
DrWebTrojan.MulDrop21.29038
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
Trapminemalicious.moderate.ml.score
SophosGeneric Reputation PUA (PUA)
IkarusPUA.Neoreklami
GDataGen:Variant.Barys.309819
JiangminTrojanDropper.Agent.gqwf
GoogleDetected
Antiy-AVLGrayWare[AdWare]/Win32.Neoreklami
XcitiumApplicUnwnt@#3okb7q91wd2uu
ArcabitTrojan.Barys.D4BA3B
ViRobotAdware.Neoreklami.7638763
ZoneAlarmHEUR:Trojan-Dropper.Win32.Agent.pef
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Agent.C5344310
McAfeeArtemis!F0251DE51BCA
MAXmalware (ai score=89)
VBA32TrojanDropper.Agent
MalwarebytesGeneric.Malware.AI.DDS
RisingAdware.Neoreklami!1.ABC4 (CLASSIC)
MaxSecureTrojan.Malware.121218.susgen
FortinetAdware/Neoreklami
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS

How to remove Barys.309819?

Barys.309819 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment