Malware

Barys.326825 removal instruction

Malware Removal

The Barys.326825 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.326825 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Barys.326825?


File Info:

name: 9800C22DD6AB95DEA50E.mlw
path: /opt/CAPEv2/storage/binaries/de98e8e069d451bd1dc577db41049052d7e55cc4ffd389f0f3eb5517f2ae69f5
crc32: 14F8D6D3
md5: 9800c22dd6ab95dea50e98b695a9547b
sha1: 1643d718d153c88aa4f6497b523abdbc1766c1c9
sha256: de98e8e069d451bd1dc577db41049052d7e55cc4ffd389f0f3eb5517f2ae69f5
sha512: 3a18b9490e9ce4ac171824cc537313765200d998c3fa9cdda77597eb9fcbc1ddaf462249e706fb886bf379993da3e7fd4e9ea0e17e5835bc4c3fd64ab7ae9729
ssdeep: 3072:bG8D6ShJdi+iOEcIlJ+k433GZ+cQRA7oTRCSAGjcc2zWm7/O2JN7RSNGx:5iMEgnq+xRA7b4l23NENm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D76441176680F629E53585F02A59B2B05539DC3224A0F8C3FAD29F7D32B3E57E921723
sha3_384: 44dce2fa4fc4c1448b39fbc43ee37b667809c7fd4825fec9e290793e69c8ddaf743d49b1b60e9191d0facd2227e9658f
ep_bytes: 6840444000e8f0ffffff000048000000
timestamp: 2012-01-06 18:22:15

Version Info:

0: [No Data]

Barys.326825 also known as:

BkavW32.AIDetectMalware
AVGWin32:AutoRun-CMZ [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.326825
FireEyeGeneric.mg.9800c22dd6ab95de
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.fm
McAfeeGenericRXKA-YF!9800C22DD6AB
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.8d153c
BaiduWin32.Trojan.Inject.n
VirITTrojan.Win32.SHeur4.MRK
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/AutoRun.VB.AQN
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Vobfus-70360
KasperskyWorm.Win32.Vobfus.dbjc
BitDefenderGen:Variant.Barys.326825
NANO-AntivirusTrojan.Win32.Diple.crsvmz
AvastWin32:AutoRun-CMZ [Trj]
TencentWorm.Win32.Vobfus.hak
SophosMal/SillyFDC-U
F-SecureTrojan.TR/Otran.aymc
DrWebTrojan.Siggen8.64518
VIPREGen:Variant.Barys.326825
TrendMicroWORM_VOBFUS.SMAB
EmsisoftGen:Variant.Barys.326825 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.326825
JiangminWorm.Vobfus.krzs
VaristW32/A-c4c4cce7!Eldorado
AviraTR/Otran.aymc
MAXmalware (ai score=80)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kazy.kwa@4m6v7n
ArcabitTrojan.Barys.D4FCA9
ViRobotTrojan.Win32.A.Diple.294912.W
ZoneAlarmWorm.Win32.Vobfus.dbjc
MicrosoftWorm:Win32/Vobfus!pz
GoogleDetected
AhnLab-V3Trojan/Win32.Diple.R126355
BitDefenderThetaAI:Packer.F67661D121
ALYacGen:Variant.Barys.326825
TACHYONTrojan/W32.VB-Agent.308556
VBA32BScope.Trojan.Diple
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMAB
RisingWorm.VobfusEx!1.99D9 (CLASSIC)
YandexTrojan.GenAsa!1iZFKuhiRA4
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Diple.EJQE!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Barys.326825?

Barys.326825 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment