Malware

How to remove “Barys.318532”?

Malware Removal

The Barys.318532 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.318532 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Barys.318532?


File Info:

name: E7E7E0E62BC1C735E31D.mlw
path: /opt/CAPEv2/storage/binaries/408cd2ed407d268e528f7c4e22792978245e41b5ed7e978e24be253e8c8e4fb5
crc32: 21E07510
md5: e7e7e0e62bc1c735e31da37767587adf
sha1: 22c9e8cabd21f5354487736b2764c7b195c1a3ab
sha256: 408cd2ed407d268e528f7c4e22792978245e41b5ed7e978e24be253e8c8e4fb5
sha512: 085c482a36eaf76cec1c39e31b72f38c677eb2cec4dcae245ff19021f97613dcbd9c3f69c8be1915ba9145a014112681c39908f607cc9c99278a47fcf97187d8
ssdeep: 49152:V296v2/2S2gfeSxwSgLHrziYsBL+pLwRlxSXkI:V296v2/2S2gu381+FmaXkI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14BD58E50EBCAC0F2CA4621B0187EF739CA696D4D5B249BE33369FE9DA5332C16437149
sha3_384: 66667a0e53ae41bff740e4e274be2ee8d3e9e125882dc81c12de545a3484c904bc0cc84dfa8aca50e21b6f9fcd0b439d
ep_bytes: 558bec6aff68b84b5d0068a03a590064
timestamp: 2021-04-22 06:50:00

Version Info:

CompanyName: CHENGDU YIWO Tech Development Co., Ltd
FileDescription: PolicyManage Dynamic Link Library
FileVersion: 5.8.0.0
InternalName: PolicyManage
LegalCopyright: Copyright (C) 2005-2011 CHENGDU YIWO Tech Development Co., Ltd. All rights reserved.
OriginalFilename: PolicyManage.exe
ProductName: PolicyMa Dynamic Link Library
ProductVersion: 5.8.0.0
Translation: 0x0804 0x04b0

Barys.318532 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ekstak.4!c
tehtrisGeneric.Malware
DrWebTrojan.MulDrop11.28728
MicroWorld-eScanGen:Variant.Barys.318532
FireEyeGeneric.mg.e7e7e0e62bc1c735
SkyhighBehavesLike.Win32.Generic.vh
ALYacGen:Variant.Barys.318532
MalwarebytesGeneric.Crypt.Trojan.DDS
ZillyaTrojan.Kryptik.Win32.3092374
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005825821 )
AlibabaTrojan:Win32/Ekstak.156249f4
K7GWTrojan ( 005825821 )
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HKHD
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan.Win32.Ekstak.gen
BitDefenderGen:Variant.Barys.318532
AvastWin32:AdwareX-gen [Adw]
TencentWin32.Trojan.Ekstak.Umhl
EmsisoftGen:Variant.Barys.318532 (B)
F-SecureHeuristic.HEUR/AGEN.1314976
VIPREGen:Variant.Barys.318532
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
VaristW32/Kryptik.DXF.gen!Eldorado
AviraHEUR/AGEN.1314976
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Ekstak
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Barys.D4DC44
ZoneAlarmHEUR:Trojan.Win32.Ekstak.gen
GDataGen:Variant.Barys.318532
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R415538
McAfeeGenericRXAA-FA!E7E7E0E62BC1
TACHYONTrojan/W32.Ekstak.2789376.C
VBA32BScope.Trojan.Ekstak
Cylanceunsafe
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.Ekstak!NE6/tesMqe4
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.73555928.susgen
FortinetW32/Kryptik.HATU!tr
AVGWin32:AdwareX-gen [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Barys.318532?

Barys.318532 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment