Malware

Barys.318198 malicious file

Malware Removal

The Barys.318198 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.318198 virus can do?

  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Barys.318198?


File Info:

name: DD6860F62C78F31BDD60.mlw
path: /opt/CAPEv2/storage/binaries/3e585e31fb3009e1aeaf45320145d55778eecd893d5addccf0f7b93cfafdd620
crc32: A187CAF9
md5: dd6860f62c78f31bdd603c0f96868d48
sha1: a5d69964e118c8d1626fe36e2e43497c670ad4f3
sha256: 3e585e31fb3009e1aeaf45320145d55778eecd893d5addccf0f7b93cfafdd620
sha512: 17baf26f7d6d87d8122c3da68ecc6e931db375bfa2b9fcdd37f5cf9d39d20999153c268d28286a219f7670b00f6c3502b806631ed8b4b85eea6ecbeeeaa5dc82
ssdeep: 768:7JeG9hs4Nchua81Lp7n5tWVi6AevXASi/qRR8J1eumsenuW+TQGqn/vmHo:7vs4y4aql5a0eIF/qRR8J1iKovX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T174436C5BBBCE0637D9A648312074273F27AAA934052F8CA3D7D15D4A3C718D69639F07
sha3_384: edcc07be7839da59bc75b0af65e1c5ed1af294253b5e838a49a7433a1a85f22c347bbf0e7bc19c5bedba868da6c1c1e3
ep_bytes: 558bec6aff687811400068e48c400064
timestamp: 2014-03-09 13:49:13

Version Info:

Comments:
CompanyName:
FileDescription: Setup/Uninstall
FileVersion: 1, 0, 0, 1
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
PrivateBuild:
ProductName:
ProductVersion:
SpecialBuild:
Translation: 0x0804 0x04b0

Barys.318198 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.318198
MalwarebytesBackdoor.Farfli
K7AntiVirusTrojan ( 0040f8a31 )
K7GWTrojan ( 0040f8a31 )
Cybereasonmalicious.62c78f
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Farfli.APO
TrendMicro-HouseCallTROJ_GEN.R011C0XHR23
AvastWin32:MalwareX-gen [Trj]
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Barys.318198
NANO-AntivirusTrojan.Win32.Strictor.cxktkh
SUPERAntiSpywareTrojan.Agent/Gen-GalPic
SophosML/PE-A
F-SecureTrojan.TR/Strictor.45732.2
TrendMicroTROJ_GEN.R011C0XHR23
McAfee-GW-EditionBehavesLike.Win32.Generic.qm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.dd6860f62c78f31b
EmsisoftGen:Variant.Barys.318198 (B)
GDataGen:Variant.Barys.318198
WebrootW32.Trojan.Gen
AviraTR/Strictor.45732.2
ArcabitTrojan.Barys.D4DAF6
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftWorm:Win32/Gamarue!ml
CynetMalicious (score: 100)
MAXmalware (ai score=80)
Cylanceunsafe
APEXMalicious
RisingTrojan.Generic@AI.100 (RDML:3Q5zQEteb+/w3C1ylp6aJQ)
BitDefenderThetaAI:Packer.31E2DED31F
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Barys.318198?

Barys.318198 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment