Malware

Barys.326825 removal tips

Malware Removal

The Barys.326825 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.326825 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Barys.326825?


File Info:

name: E3CFE844DC8CAAF8248C.mlw
path: /opt/CAPEv2/storage/binaries/5d90b83b00406f6b095c1c56ce8b0e4e34b379da18f82e770f9ed42bc9c0bf7b
crc32: 0B33D72F
md5: e3cfe844dc8caaf8248ca65c9803e9f4
sha1: c5fec2d51fed83f063c3831d1d3971230326b7cd
sha256: 5d90b83b00406f6b095c1c56ce8b0e4e34b379da18f82e770f9ed42bc9c0bf7b
sha512: 9dd20c50aa33315706531095965f4a4d3b758a011c75d1c21eb0ca0841ac55fa72f75b5b684cc22c632a8004d7dc8effe000241567ed2373d62be5d4263dc06d
ssdeep: 3072:o0A2afa1Zbn4DpS41Zr8EbjfmNwXl1RgxfGDP8F2dqMOkeuF7SzoI:zay1Zz4Dp7R8cA0l1RpLtJj7SkI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DB5473267390FB2DD524C1F03A4A83A0A47AED7255E46803F6C13F6A77B1DABE121717
sha3_384: 324bede77c3b727a382848e488f24c0178db224a9a2f2f5ba92951cd684fc680f0becf920be1066dfda8b83ffca24329
ep_bytes: 68e44a4000e8eeffffff000000000000
timestamp: 2012-01-07 18:24:49

Version Info:

0: [No Data]

Barys.326825 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Barys.326825
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.eq
Cylanceunsafe
VIPREGen:Variant.Barys.326825
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.VBObfus.f
VirITTrojan.Win32.SHeur4.MTF
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AQN
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMAB
ClamAVWin.Trojan.Vobfus-35
KasperskyWorm.Win32.Vobfus.dgpv
BitDefenderGen:Variant.Barys.326825
NANO-AntivirusTrojan.Win32.Jorik.khcnas
AvastWin32:AutoRun-CMZ [Trj]
TencentWorm.Win32.Vobfus.hn
EmsisoftGen:Variant.Barys.326825 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebTrojan.VbCrypt.150
TrendMicroWORM_VOBFUS.SMAB
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.e3cfe844dc8caaf8
SophosMal/SillyFDC-U
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=81)
GoogleDetected
AviraTR/Patched.Ren.Gen
VaristW32/Vobfus.AI.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
ArcabitTrojan.Barys.D4FCA9
ViRobotWorm.Win32.A.WBNA.290816.BY
ZoneAlarmWorm.Win32.Vobfus.dgpv
GDataGen:Variant.Barys.326825
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Jorik.R490516
Acronissuspicious
VBA32TScope.Trojan.VB
ALYacGen:Variant.Barys.326825
TACHYONTrojan/W32.VB-Agent.299008.BU
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingWorm.Pronoy!1.9A2F (CLASSIC)
YandexTrojan.GenAsa!iefZtqwFMM4
IkarusSality.Win32
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Diple.EJQE!tr
BitDefenderThetaAI:Packer.8DE7EE741E
AVGWin32:AutoRun-CMZ [Trj]
Cybereasonmalicious.4dc8ca
DeepInstinctMALICIOUS

How to remove Barys.326825?

Barys.326825 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment