Malware

Application.Barys.6305 (file analysis)

Malware Removal

The Application.Barys.6305 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Barys.6305 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Application.Barys.6305?


File Info:

name: E6BF1EBB3938E2934329.mlw
path: /opt/CAPEv2/storage/binaries/176472c0090e90680ae5653f916320098c5f6720f92d6e93817b6d5d16828e3b
crc32: D98FBE8B
md5: e6bf1ebb3938e2934329f1bc6bc1c074
sha1: 5f507ba85da35a993e7e9ed47a967ebc34320fd1
sha256: 176472c0090e90680ae5653f916320098c5f6720f92d6e93817b6d5d16828e3b
sha512: 1dd65154959487845efd9fb649acb48a199c266c692afd6b9337fcdc14291849d2650e57fb4b18691a31a28b1d332e7d945f0d35bc3a8f9f8637e0bc88b11517
ssdeep: 1536:jiej+M/6v0pBdQrAa/JOf5MFzF0K1/lex4vbADuumW9I3iYIGcmAhji91:B5SOOAa/GAFZbAdmAFi91
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17DF3A5387707D4A1D105A53522FA88FA75B7F85D5B87208FA7883B626CB0E085DB6F43
sha3_384: 83c49c0e6f59d3a578cc562fd2c9f008fabbd32142fae5e41ec514e363c02cf8324a0f6b92bb23c3d7905746af3e284e
ep_bytes: 6808134000e8f0ffffff000060000000
timestamp: 2012-08-08 06:18:37

Version Info:

Translation: 0x0409 0x04b0
Comments: Buckwashing Sciarid
CompanyName: Buckwashing Sciarid
FileDescription: Buckwashing Sciarid
LegalCopyright: Buckwashing Sciarid
LegalTrademarks: Buckwashing Sciarid
ProductName: Buckwashing Sciarid
FileVersion: 8.00
ProductVersion: 8.00
InternalName: overpowerful
OriginalFilename: overpowerful.exe

Application.Barys.6305 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.tsnn
CynetMalicious (score: 100)
CAT-QuickHealTrojan.JorikMF.S28494457
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeGenDownloader.rv
Cylanceunsafe
VIPREGen:Variant.Application.Barys.6305
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderGen:Variant.Application.Barys.6305
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Worm.Pronny.fp
SymantecW32.Changeup!gen20
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.CF
APEXMalicious
ClamAVWin.Malware.Vobfus-6793191-0
KasperskyTrojan.Win32.Jorik.Vobfus.fbor
AlibabaWorm:Win32/vobfus.1030
NANO-AntivirusTrojan.Win32.Jorik.coonis
MicroWorld-eScanGen:Variant.Application.Barys.6305
TencentTrojan.Win32.Vobfus.kqq
TACHYONTrojan/W32.Jorik.163840
EmsisoftGen:Variant.Application.Barys.6305 (B)
F-SecureWorm.WORM/Vobfus.GJ.1
DrWebWin32.HLLW.Autoruner2.16029
ZillyaTrojan.Jorik.Win32.1097616
TrendMicroWORM_VOBFUS.SM01
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.e6bf1ebb3938e293
SophosMal/Kovter-W
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Jorik.gwhv
WebrootW32.Obfuscated.Gen
GoogleDetected
AviraWORM/Vobfus.GJ.1
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.997
MicrosoftWorm:Win32/Vobfus.GO
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
ArcabitTrojan.Application.Barys.D18A1
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
ZoneAlarmTrojan.Win32.Jorik.Vobfus.fbor
GDataWin32.Trojan.PSE.1OJHJNG
VaristW32/Vobfus.AQ.gen!Eldorado
AhnLab-V3Trojan/Win32.Jorik.R42854
ALYacGen:Variant.Application.Barys.6305
MAXmalware (ai score=79)
DeepInstinctMALICIOUS
VBA32TScope.Trojan.VB
MalwarebytesPronny.Worm.Spreader.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM01
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!T3Gv5kmBXIo
IkarusVirus.Win32.Cryptor
MaxSecureTrojan.Malware.4353008.susgen
FortinetW32/Injector.ADYA!tr
BitDefenderThetaAI:Packer.A6217C4320
AVGWin32:VBCrypt-BJA [Trj]
AvastWin32:VBCrypt-BJA [Trj]

How to remove Application.Barys.6305?

Application.Barys.6305 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment