Malware

Should I remove “Barys.431324”?

Malware Removal

The Barys.431324 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.431324 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Barys.431324?


File Info:

name: F7A807D3686AEDFD97B3.mlw
path: /opt/CAPEv2/storage/binaries/51d327bd097e10599196469efecaad16b86892df47b467474b74609fde48ba3c
crc32: 54262083
md5: f7a807d3686aedfd97b304a51a4579b1
sha1: 8ae5bc3b6680b0dbb81a9c2d6d79508b32e62b67
sha256: 51d327bd097e10599196469efecaad16b86892df47b467474b74609fde48ba3c
sha512: bf72f399888e5f0bc90532bf41d4af7b015f3a49558a1f9f25988a9a92cedaf1cefdcf8dba5de7137efe3c650c0ec4db19ef8b40e918ce887e4ab12f95ad5c2c
ssdeep: 6144:OFQxSU9nGAzCuMX8NQzlJ/XIvbcnpjJegwmyDwABbxxJa/YES3G2i:UfU5GG/MXxlJAUeg9ajVDa/ZS22i
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11025370E13660183E0062AB6A9DDDA5354C0E8FE6AF6D6627C847DEF34213BC951376F
sha3_384: f0a021461496175479b8c72ed2ca111a5b9df0807d87d10a50d1c5a0ca21d1acc907488ab8e1a1c710ee3fb5922eb8a1
ep_bytes: 7070a89915cb978e7670a8fcb8d9805c
timestamp: 1972-09-27 00:00:00

Version Info:

0: [No Data]

Barys.431324 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.431324
FireEyeGeneric.mg.f7a807d3686aedfd
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Barys.431324
SangforTrojan.Win32.Save.a
Cybereasonmalicious.b6680b
BitDefenderThetaGen:NN.ZexaF.36350.88Z@a81Hwbc
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 100)
TrendMicro-HouseCallTROJ_GEN.R023H09HN23
ClamAVWin.Packed.Dridex-9860931-1
BitDefenderGen:Variant.Barys.431324
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Barys.431324 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
Trapminemalicious.moderate.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.431324
AviraTR/Crypt.ZPACK.Gen
ArcabitTrojan.Barys.D694DC
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
Acronissuspicious
MAXmalware (ai score=84)
Cylanceunsafe
APEXMalicious
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.6437!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Barys.431324?

Barys.431324 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment