Malware

What is “Barys.948”?

Malware Removal

The Barys.948 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.948 virus can do?

  • Authenticode signature is invalid

How to determine Barys.948?


File Info:

name: AB3051727131B75D113D.mlw
path: /opt/CAPEv2/storage/binaries/aca79fffc8517ca5b4dd8888c118e6d2d7988796dff538354b959d6ca06202fe
crc32: 7C549E34
md5: ab3051727131b75d113d942640676892
sha1: 52618f89acfca549fe6637b7d9abe1be3b99007a
sha256: aca79fffc8517ca5b4dd8888c118e6d2d7988796dff538354b959d6ca06202fe
sha512: ac49c2569c3a1588031e23bc79ca426a2937ec80df5b347665a6f3c28f328687455cc9302deab0f9a848bc13df77ae199e6c7f24eed1e459159cff1aed5f5a91
ssdeep: 1536:AMiw1iFAE+/Dc3CJQ3DXgLtxkWPtEYreRQtuAyU1rC:A1qFGOeRQtHyUhC
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1CAA36D013C97C1B3D049497F85C287D16BBF2D03BBE6A4EFFF5406895AA02C16A796B1
sha3_384: f9e90a3927412ee4570fed0d342781987f3f5ce2156c7c17ee4c1e422d6836b4f505e5f7f22dea136ae5b61e0a70429e
ep_bytes: 837c2408017505e8ff5a0000ff742404
timestamp: 2009-12-09 07:58:26

Version Info:

0: [No Data]

Barys.948 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.948
ClamAVWin.Trojan.Downloader-3779
FireEyeGeneric.mg.ab3051727131b75d
McAfeeDownloader-CFE
ZillyaTrojan.Brownsid.Win32.10
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:Win32/Brownsid.f4bcf614
K7GWTrojan ( 004ca6d51 )
K7AntiVirusTrojan ( 004ca6d51 )
ArcabitTrojan.Barys.948
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Brownsid.D
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.948
NANO-AntivirusTrojan.Win32.Agent.egpvt
AvastWin32:TrojanX-gen [Trj]
RisingDownloader.Agent!8.B23 (TFE:6:hlHXs0gOlrD)
EmsisoftGen:Variant.Barys.948 (B)
F-SecureHeuristic.HEUR/AGEN.1301889
DrWebTrojan.DownLoader5.22969
VIPREGen:Variant.Barys.948
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.Agent
JiangminTrojan/Generic.rxvf
WebrootW32.Malware.Downloader
GoogleDetected
AviraHEUR/AGEN.1301889
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Trojan.Generic.a
XcitiumMalware@#3ovkk1eh51ilk
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Barys.948
VaristW32/Risk.VFFE-3059
BitDefenderThetaGen:NN.ZedlaF.36744.gu4@aKmXpshi
ALYacTrojan.Downloader.Agent.serv
MAXmalware (ai score=100)
VBA32BScope.Trojan.Download
Cylanceunsafe
PandaGeneric Malware
TencentWin32.Trojan.Generic.Timw
YandexTrojan.GenAsa!g4nbA0dmSdQ
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.1521242.susgen
FortinetW32/CFE!tr.dldr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Barys.948?

Barys.948 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment