Malware

Barys.319924 removal

Malware Removal

The Barys.319924 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.319924 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Barys.319924?


File Info:

name: ADD65CD18B6ADF799F5F.mlw
path: /opt/CAPEv2/storage/binaries/96b081fe0d0a567eb53fe3718458781553539be02d26ccfff32e2f2e184a33a6
crc32: 3214E4B5
md5: add65cd18b6adf799f5f9bf9ed5f572e
sha1: 77d1b8b6bf41a02c731488509234535730e94d33
sha256: 96b081fe0d0a567eb53fe3718458781553539be02d26ccfff32e2f2e184a33a6
sha512: 83b20bbfe0c59fb2fca6898d35d5e073bce37701a5a6d2b85232971c928c2509ead9c4257b0144780cf068a9d613c1431ddc0cb61094098894b22aaac6f41701
ssdeep: 3072:lBOPmb+WoRDrMW7dB+aAwVJnzNiaG1fU0:6xBpzAd7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FE15F55197507958C8BB03B48DEEAAE677355D24C726DCA6F3422ADF86D123183C2F83
sha3_384: 2bd961076da3d743f269af30e840f201ef8c16a668ae618d0bf372d353a1c864633bdbbd9ee3e17da8684bdd86a4598e
ep_bytes: 68789d4400e8f0ffffff000050000000
timestamp: 2014-06-15 16:17:49

Version Info:

Translation: 0x0409 0x04b0
Comments: Þ2QIBwì±8Enòa蜜sÁmz
CompanyName: žKj7rt£žnœBìH™svÚõjœ
FileDescription: ™kyVdžHzƒzyoœò1ÞDQDz
LegalCopyright: £võœœæO±žÚzs1œ3BBOœB
LegalTrademarks: zœ«zOõ3qsœwõZžœÞõMžh
ProductName: 4xkœÚ±uœ0sòÚFHkœBèHÞ
FileVersion: 7.01.0022
ProductVersion: 7.01.0022
InternalName: limpo
OriginalFilename: limpo.exe

Barys.319924 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.319924
ClamAVWin.Dropper.DarkKomet-9204913-0
FireEyeGeneric.mg.add65cd18b6adf79
CAT-QuickHealTrojan.VBCrypt.MF.82
McAfeeGenericRXAE-LP!ADD65CD18B6A
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2930916
Sangfor[MICROSOFT VISUAL BASIC V6.0]
K7AntiVirusTrojan ( 0049d96f1 )
K7GWTrojan ( 0049d96f1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Inject2.AVPP
CyrenW32/A-c13828ea!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.AYWH
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agent.nesavs
BitDefenderGen:Variant.Barys.319924
NANO-AntivirusTrojan.Win32.KillFiles.fmiltx
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10b41135
Ad-AwareGen:Variant.Barys.319924
SophosMal/Generic-S
ComodoTrojWare.Win32.VB.DRPF@5hzrzj
DrWebTrojan.KillFiles.16371
VIPREGen:Variant.Barys.319924
TrendMicroTROJ_GEN.R014C0PHH22
McAfee-GW-EditionGenericRXAE-LP!ADD65CD18B6A
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Barys.319924 (B)
IkarusTrojan.Win32.Klovbot
GDataGen:Variant.Barys.319924
JiangminTrojan/Agent.hzsy
AviraTR/Symmi.olaks
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.51F4
MicrosoftTrojan:Win32/Wacatac.A!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Symmi.R139961
BitDefenderThetaGen:NN.ZevbaF.34606.6m3@a8vZD8oi
ALYacGen:Variant.Barys.319924
TACHYONTrojan/W32.VB-Agent.954422
VBA32Trojan.Agent
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTROJ_GEN.R014C0PHH22
RisingWorm.Rebhip!8.B31 (TFE:3:0hsExmn7lzQ)
YandexTrojan.GenAsa!xBQWsEuI47M
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.BLMO!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.18b6ad
PandaTrj/Genetic.gen

How to remove Barys.319924?

Barys.319924 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment