Malware

Barys.381598 (B) removal tips

Malware Removal

The Barys.381598 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.381598 (B) virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Barys.381598 (B)?


File Info:

name: 976E556BFA7B7802BEC3.mlw
path: /opt/CAPEv2/storage/binaries/4a377aa865e80bad9bf3492a3de093b4e87a951010b655f345f6c9ab59de022e
crc32: 9CC4EC4A
md5: 976e556bfa7b7802bec345617e60d7e5
sha1: d53e820776de790e88b25d707ebd3cf7aac243ca
sha256: 4a377aa865e80bad9bf3492a3de093b4e87a951010b655f345f6c9ab59de022e
sha512: 6e4825b1d722a402799010e79517745ec2e5cc0b69c8d71c08bd139184abeff51f70c28d49c8954a6f64e6ace6a2f0e065ae0f509ad861d2d16dfd8161fcef62
ssdeep: 96:hy859x0P8Madp32kJ7DLCY+2sN/ITYl10ES/l:F5oLMg6R0N/iY+/
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T174C1741BD792C872FEB41A7B0E8B14D6687BCC255A7C7BA0F1D05C801284C0D9FCB95A
sha3_384: 9bd6b66bbb7aa07d9735d91a6eff29bd4cac1e859d6fe9d644e4a6b42da52ca3fd0d8775e45cda5353b2b52b9bc20161
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2013-06-12 12:49:36

Version Info:

0: [No Data]

Barys.381598 (B) also known as:

BkavW32.FamVT.DebrisA.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.381598
FireEyeGeneric.mg.976e556bfa7b7802
CAT-QuickHealTrojan.Agent.WL
SkyhighBehavesLike.Win32.Worm.zt
McAfeeW32/Worm-FJV!976E556BFA7B
MalwarebytesBundpil.Worm.AutoRun.DDS
ZillyaWorm.DebrisGen.Win32.11
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (D)
K7GWEmailWorm ( 0040f5281 )
K7AntiVirusEmailWorm ( 0040f5281 )
BitDefenderThetaGen:NN.ZedlaF.36802.aq5@ae9rVOn
VirITWorm.Win32.Generic.GRN
SymantecDownloader.Dromedan
tehtrisGeneric.Malware
ESET-NOD32Win32/Bundpil.AO
APEXMalicious
TrendMicro-HouseCallWORM_GAMARUE.SML
ClamAVWin.Adware.Downware-251
KasperskyWorm.Win32.Debris.b
BitDefenderGen:Variant.Barys.381598
NANO-AntivirusTrojan.Win32.Debris.cqkxyu
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
AvastWin32:Sg-I [Trj]
TencentWorm.Win32.Debris.c
TACHYONWorm/W32.Debris.6118.B
SophosW32/Gamarue-BL
BaiduWin32.Worm.Bundpil.y
F-SecureWorm.WORM/Gamarue.511265
DrWebTrojan.MulDrop4.25343
VIPREGen:Variant.Barys.381598
TrendMicroWORM_GAMARUE.SML
EmsisoftGen:Variant.Barys.381598 (B)
IkarusWorm.Win32.Bundpil
JiangminTrojan/Generic.axdgt
GoogleDetected
AviraWORM/Gamarue.511265
VaristW32/Csyr.B.gen!Eldorado
Antiy-AVLWorm/Win32.Debris
Kingsoftmalware.kb.a.998
MicrosoftTrojanDownloader:Win32/Andromeda!pz
XcitiumWorm.Win32.Bundpil.AH@4yjufs
ArcabitTrojan.Barys.D5D29E
ZoneAlarmWorm.Win32.Debris.b
GDataWin32.Worm.Bundpil.B
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Debris.R71328
VBA32Worm.Gamarue
MAXmalware (ai score=82)
Cylanceunsafe
PandaGeneric Malware
RisingWorm.Gamarue!1.9CB3 (CLASSIC)
YandexTrojan.GenAsa!VJN5611Pa6Y
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.Debris.Gen
FortinetW32/Bundpil.AO!tr
AVGWin32:Sg-I [Trj]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Gamarue.66c7f521

How to remove Barys.381598 (B)?

Barys.381598 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment