Malware

Barys.412050 removal guide

Malware Removal

The Barys.412050 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.412050 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Barys.412050?


File Info:

name: F80C2CEB883E3FBF5113.mlw
path: /opt/CAPEv2/storage/binaries/8dd185195bb0e7c4c7c43a5998a0cd37350a6a5b315b5d2f02314c5c2606202f
crc32: 90DCDA75
md5: f80c2ceb883e3fbf511374646b7966c3
sha1: 330ade5833d8604384778fe7eac211a0a050e22e
sha256: 8dd185195bb0e7c4c7c43a5998a0cd37350a6a5b315b5d2f02314c5c2606202f
sha512: be0590079b193955e1666242a5c13b7d4171d820717a29180e3ac457b6476560ad07305c525b3c95ce80d66037e7cd0156b8df9d3fed40ad0c19b5978d840fc8
ssdeep: 49152:M+pOu/OyfJ57S93elPOyG8BjKqo4mN6hmjHeaTUf960cUEBlLz0S5QghEFv:fYHnOOyGAKqx+TUf96sS5
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1CB466C27B784653EC09B0B395867A314993F7B6239128C5B7BF4488C8F365437E3A64B
sha3_384: d262da7d4b9e66df5dff66685b4437bf071e4066487e00eafbd50fc89fb30bdec7219375f53e16ac2797f3105543a759
ep_bytes: 558bec83c4c0b800098c00e8f0f4b3ff
timestamp: 2024-01-08 16:23:35

Version Info:

0: [No Data]

Barys.412050 also known as:

LionicTrojan.Win32.Grandoreiro.7!c
AVGWin32:SpywareX-gen [Trj]
MicroWorld-eScanGen:Variant.Barys.412050
FireEyeGen:Variant.Barys.412050
SkyhighBehavesLike.Win32.BadFile.th
McAfeeArtemis!F80C2CEB883E
SangforSpyware.Win32.Grandoreiro.Vrlm
K7AntiVirusSpyware ( 005a3f4a1 )
AlibabaTrojanBanker:Win32/Grandoreiro.a25b1211
K7GWSpyware ( 005a3f4a1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Grandoreiro.CA
CynetMalicious (score: 100)
APEXMalicious
KasperskyUDS:Trojan-Banker.Win32.Grandoreiro.gen
BitDefenderGen:Variant.Barys.412050
AvastWin32:SpywareX-gen [Trj]
TencentMalware.Win32.Gencirc.13fce153
EmsisoftGen:Variant.Barys.412050 (B)
F-SecureHeuristic.HEUR/AGEN.1364204
VIPREGen:Variant.Barys.412050
TrendMicroTROJ_GEN.R002C0XAE24
SophosMal/Generic-S
AviraHEUR/AGEN.1364204
Antiy-AVLTrojan[Spy]/Win32.Grandoreiro
KingsoftWin32.Trojan-Banker.Grandoreiro.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Barys.D64992
ZoneAlarmUDS:Trojan-Banker.Win32.Grandoreiro.gen
GDataGen:Variant.Barys.412050
VaristW32/ABRisk.QQJG-1017
AhnLab-V3Malware/Win.Generic.C5570766
ALYacGen:Variant.Barys.412050
MAXmalware (ai score=87)
Cylanceunsafe
PandaTrj/RnkBend.A
TrendMicro-HouseCallTROJ_GEN.R002C0XAE24
RisingSpyware.Grandoreiro!8.F2CC (TFE:6:HMeus8CT5pN)
IkarusTrojan-Spy.Win32.Grandoreiro
MaxSecureTrojan.Malware.102062852.susgen
FortinetW32/Grandoreiro.CB!tr.spy
DeepInstinctMALICIOUS

How to remove Barys.412050?

Barys.412050 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment