Malware

About “Application.Barys.6305” infection

Malware Removal

The Application.Barys.6305 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Barys.6305 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Application.Barys.6305?


File Info:

name: DF31DB45FF40BB714144.mlw
path: /opt/CAPEv2/storage/binaries/4c0fa20d8121857727796b1ee5f36dc441b796e14e3752e2382d753028449d26
crc32: 960CDEC8
md5: df31db45ff40bb71414466a5d20bf0a0
sha1: 99e6f14b0fe87e10f72063ee412cbcc83b801b6b
sha256: 4c0fa20d8121857727796b1ee5f36dc441b796e14e3752e2382d753028449d26
sha512: e7d4f43614782614cefc1e5616f448ad7f5f0ef3837b0826b66fc6e56143877ab6c8e31aa28d9db17c0b384af252211e7b6b3d9d1037e44e041efb5f2e72fa25
ssdeep: 3072:K2/acOaPAX7EjWafJMgE/2DyRuBzMuDuf3tbFR9EBoPfnvOYnM:t/YaI7EjWaLBzMsgJve
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12CE39478B24AA071D6E1663D2647CFEB1017681DEC0BA19EA7583F9F6934F44089CF63
sha3_384: 290db8fbb92a295add212461f6aff029287907bb4434963dcfb0b50e1bbd0a04ddff94a78ec81c14c8b2f933dc73516f
ep_bytes: 6824134000e8eeffffff000000000000
timestamp: 2012-08-01 05:24:05

Version Info:

Translation: 0x0409 0x04b0
Comments: Abiurasse
CompanyName: Abiurasse
FileDescription: Abiurasse
LegalCopyright: Abiurasse
LegalTrademarks: Abiurasse
ProductName: Abiurasse
FileVersion: 4.00
ProductVersion: 4.00
InternalName: Pythium
OriginalFilename: Pythium.exe

Application.Barys.6305 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.lwz0
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner1.24207
CynetMalicious (score: 100)
FireEyeGeneric.mg.df31db45ff40bb71
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeGenDownloader.rv
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
AlibabaWorm:Win32/Jorik.dc86981d
K7GWEmailWorm ( 003c363a1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZevbaF.36744.im0@auqv0Gei
VirITTrojan.Win32.Vobfus.FAWF
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/Pronny.BZ
APEXMalicious
ClamAVWin.Malware.Vobfus-6813193-0
KasperskyTrojan.Win32.Jorik.Vobfus.fawf
BitDefenderGen:Variant.Application.Barys.6305
NANO-AntivirusTrojan.Win32.Jorik.jvvlcb
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
MicroWorld-eScanGen:Variant.Application.Barys.6305
AvastWin32:VB-ADXV [Trj]
TencentWorm.Win32.Vobfus.q
TACHYONTrojan/W32.Jorik.143360.B
EmsisoftGen:Variant.Application.Barys.6305 (B)
F-SecureTrojan.TR/Jorik.Vobfu.fawf
BaiduWin32.Worm.Pronny.dd
VIPREGen:Variant.Application.Barys.6305
TrendMicroWORM_VOBFUS.SM01
Trapminemalicious.high.ml.score
SophosMal/Kovter-W
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Application.Barys.6305
JiangminTrojan/Jorik.gqve
WebrootW32.Malware.Gen
VaristW32/VB.HD.gen!Eldorado
AviraTR/Jorik.Vobfu.fawf
Antiy-AVLWorm/Win32.WBNA.gen
KingsoftWin32.Trojan.Jorik.Vobfus
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
ArcabitTrojan.Application.Barys.D18A1
ViRobotTrojan.Win32.Jorik.143360.D
ZoneAlarmTrojan.Win32.Jorik.Vobfus.fawf
MicrosoftWorm:Win32/Vobfus.GH
GoogleDetected
AhnLab-V3Worm/Win32.VBNA.R31483
Acronissuspicious
VBA32TScope.Trojan.VB
ALYacGen:Variant.Application.Barys.6305
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SM01
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.Vobfus!k9D5PZ4iyoI
IkarusWorm.Win32.VBNA
MaxSecureTrojan.Malware.4316045.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-ADXV [Trj]
Cybereasonmalicious.b0fe87
DeepInstinctMALICIOUS

How to remove Application.Barys.6305?

Application.Barys.6305 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment