Malware

Application.Barys.6305 malicious file

Malware Removal

The Application.Barys.6305 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Barys.6305 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Application.Barys.6305?


File Info:

name: DE7545B64403B4E695D9.mlw
path: /opt/CAPEv2/storage/binaries/0fe29eafe8a0a32341f9f89ad5cb0450b42efdd96412eedc6d6ee5dc2322bb6f
crc32: FD2E82BD
md5: de7545b64403b4e695d9e4ec4a961ab7
sha1: b2bca1276e86672f660800dac41d9adab531dadc
sha256: 0fe29eafe8a0a32341f9f89ad5cb0450b42efdd96412eedc6d6ee5dc2322bb6f
sha512: d435aee84984fc30975630e35f1b9547bdf709de32fb4100f9cbe0e8034bba38307f1124f781dd567a79915669bc2cd8d9d2ad75c3f303594ab20d30ee7a8e0c
ssdeep: 3072:8Ge2fdLbEamM2YhFEryJVVtOTI4BkcKmPcfNVw8:3dLAaHFHVVtO7KmkfNVL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13414F73AFA8193A5C12A5A3639EBCBF505633C0C4F47840BA96433ED1DB2F741D69A47
sha3_384: bf27e18d610a7d889b5d1581e2f378f85d1f2d2dddb63cae72bd04067c22be64520f3559a4cf0f80fe2f3c7d98da4e39
ep_bytes: 6880134000e8eeffffff000000000000
timestamp: 2012-08-14 02:23:05

Version Info:

Translation: 0x0409 0x04b0
Comments: scomunica longeval
CompanyName: scomunica longeval
FileDescription: scomunica longeval
LegalCopyright: scomunica longeval
LegalTrademarks: scomunica longeval
ProductName: scomunica longeval
FileVersion: 8.20
ProductVersion: 8.20
InternalName: Halide
OriginalFilename: Halide.exe

Application.Barys.6305 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner1.24947
MicroWorld-eScanGen:Variant.Application.Barys.6305
ClamAVWin.Trojan.Vobfus-40
CAT-QuickHealTrojan.JorikMF.S27797009
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeGenDownloader.rv
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.76e866
BitDefenderThetaGen:NN.ZevbaF.36744.mm0@aWPdy6bi
VirITWorm.Win32.X-Autorun.BKXN
SymantecW32.Changeup!gen20
ESET-NOD32Win32/Pronny.CM
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Jorik.Vobfus.fcnj
BitDefenderGen:Variant.Application.Barys.6305
NANO-AntivirusTrojan.Win32.Jorik.covkve
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-AEBR [Trj]
TencentWorm.Win32.Vobfus.m
EmsisoftGen:Variant.Application.Barys.6305 (B)
F-SecureTrojan.TR/Barys.A.6305
BaiduWin32.Worm.Pronny.eb
VIPREGen:Variant.Application.Barys.6305
TrendMicroWORM_VOBFUS.SM01
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.de7545b64403b4e6
SophosMal/Kovter-W
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Application.Barys.6305
JiangminTrojan/Jorik.hwar
WebrootW32.Obfuscated.Gen
GoogleDetected
AviraTR/Barys.A.6305
MAXmalware (ai score=76)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.988
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
ArcabitTrojan.Application.Barys.D18A1
ZoneAlarmTrojan.Win32.Jorik.Vobfus.fcnj
MicrosoftWorm:Win32/Vobfus.HF
VaristW32/VB.HD.gen!Eldorado
AhnLab-V3Trojan/Win32.Jorik.R33575
VBA32Trojan.Vobfus
ALYacGen:Variant.Application.Barys.6305
TACHYONTrojan/W32.VB-Jorik.196608.J
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM01
RisingWorm.VobfusEx!1.99DC (CLASSIC)
YandexTrojan.GenAsa!3dwChsaCCXs
IkarusTrojan.Win32.Jorik
MaxSecureTrojan.Malware.4386365.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-AEBR [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Application.Barys.6305?

Application.Barys.6305 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment