Malware

Barys.323870 removal guide

Malware Removal

The Barys.323870 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.323870 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Barys.323870?


File Info:

name: ABDCAD72FDB4B09601E7.mlw
path: /opt/CAPEv2/storage/binaries/3e1d10e5adb281c7d8bd09027e757b8b523135f0b31bbf1e2f155e7e2c9dc02c
crc32: 17E5DC2C
md5: abdcad72fdb4b09601e7b55c54e59500
sha1: a8c80ea0e05e787a80dd6c4608ed69bec58809c7
sha256: 3e1d10e5adb281c7d8bd09027e757b8b523135f0b31bbf1e2f155e7e2c9dc02c
sha512: 78a2d4c7be87b1ebddcad1c53c0cb198d9fa4413af214d65861611feccc5796e25653aaaaa3a242754b6dbf0fc2a5282f0ad612038524adea011219117b459c0
ssdeep: 1536:zny66oS9l8tZ602P0UGfIV+zv/0I9Q4pP8EHn+ZnRE6B81Rufsluy1yVig3:byWce2P0UGfIkzvXaLy1yl3
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1A0145B036A9602F9F916023030B72F72D6399F525B8AE68F5723FCD69C395627836707
sha3_384: 9bceff492762aff4a5d7aaed6c808a28d02fca1d98655f6a946b87088725cbf0d8dfec7c3964b71f4db7cbda7bb2caa9
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2012-09-07 11:53:45

Version Info:

Comments:
CompanyName:
FileDescription: ghfddg333
FileVersion: 111, 65, 22, 654
InternalName: ghfddg333
LegalCopyright: Copyright 1997
LegalTrademarks:
OLESelfRegister:
OriginalFilename: ghfddg333.dll
PrivateBuild:
ProductName: ghfddg333 Module
ProductVersion: 111, 65, 22, 654
SpecialBuild:
Translation: 0x0409 0x04b0

Barys.323870 also known as:

BkavW32.FamVT.CidoxHQc.Trojan
LionicTrojan.Win32.Mapler.lCTK
DrWebTrojan.StartPage.47375
MicroWorld-eScanGen:Variant.Barys.323870
ClamAVWin.Malware.Barys-9946903-0
FireEyeGeneric.mg.abdcad72fdb4b096
SkyhighBehavesLike.Win32.Worm.cz
ALYacGen:Variant.Barys.323870
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusPassword-Stealer ( 005148c31 )
AlibabaRansom:Win32/Cidox.67be55a9
K7GWPassword-Stealer ( 005148c31 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZedlaF.36680.my8@aqjIXbpj
VirITTrojan.Win32.OnlineGames4.UUL
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.OnLineGames.QOX
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Cidox.aaax
BitDefenderGen:Variant.Barys.323870
NANO-AntivirusTrojan.Win32.StartPage.bbwhxe
AvastWin32:OnLineGames-GGZ [Trj]
TencentMalware.Win32.Gencirc.10b31697
SophosMal/GamerPWS-C
F-SecureTrojan.TR/PSW.OnlGame.1258
BaiduWin32.Trojan-PSW.OLGames.t
VIPREGen:Variant.Barys.323870
TrendMicroTROJ_ONLINEGAMES_BK082C58.TOMC
EmsisoftGen:Variant.Barys.323870 (B)
IkarusTrojan-PWS.OnlineGames
GDataWin32.Trojan.PSE.17CUJBQ
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/PSW.OnlGame.1258
Antiy-AVLTrojan[Ransom]/Win32.Cidox
KingsoftWin32.Troj.Undef.a
XcitiumTrojWare.Win32.PSW.Agent.QAT@4p1h5t
ArcabitTrojan.Barys.D4F11E
ViRobotTrojan.Win32.PSWIGames.199680.D
ZoneAlarmTrojan-Ransom.Win32.Cidox.aaax
MicrosoftPWS:Win32/Enterak.A
VaristW32/OnlineGames.IH.gen!Eldorado
AhnLab-V3Trojan/Win32.OnlineGameHack.R41629
McAfeePWS-OnlineGames.lj
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Gamania
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/OnlineGames.HEU
TrendMicro-HouseCallTROJ_ONLINEGAMES_BK082C58.TOMC
RisingStealer.OnlineGames!1.64BA (CLASSIC)
YandexTrojan.GenAsa!07P/cXlOKZA
SentinelOneStatic AI – Malicious PE
FortinetW32/Magania.GKL!tr
AVGWin32:OnLineGames-GGZ [Trj]
DeepInstinctMALICIOUS

How to remove Barys.323870?

Barys.323870 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment