Malware

Application.Barys.6305 (B) removal guide

Malware Removal

The Application.Barys.6305 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Barys.6305 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Application.Barys.6305 (B)?


File Info:

name: CDCEEBCE3DC827B49CCC.mlw
path: /opt/CAPEv2/storage/binaries/e4215a2214325753962e277e1fcc918c1bad881e058a23b61dd9d104a622ffdd
crc32: B533D17F
md5: cdceebce3dc827b49cccbadd60cd15d1
sha1: 95f0536d2af2863004d15e0100ed73e8b64f0b40
sha256: e4215a2214325753962e277e1fcc918c1bad881e058a23b61dd9d104a622ffdd
sha512: 67838c48e90d81dbcf7fd8aca4fb21cf5e984eac606e392975173253de0870d0ed678f2958da5448bf2bfd34ff7787095f3f38eda561b30b3d7030c2a27cebcf
ssdeep: 3072:moHcXgjEfW+zx3ad1bCUkZArSnXBUlyiaCQohRnlX:ykMV3ad1bCUkZArSnXBUlyiaC3L
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T168D3712BBF9D9890EA1911782EF7C7F51262AC187E0751472A643B6FE9B3F105C1CA13
sha3_384: 85ae2cb30e54e18d3ddc9f3870f9462eaf342110f1b3152fb12d5359ed45d74ddf3a9bcad86ad6a90fc987fcd876bc38
ep_bytes: 68c4124000e8eeffffff000000000000
timestamp: 2012-08-10 05:07:40

Version Info:

Translation: 0x0409 0x04b0
Comments: Prehydration misapprehensively Bushrope
CompanyName: Prehydration misapprehensively Bushrope
FileDescription: Prehydration misapprehensively Bushrope
LegalCopyright: Prehydration misapprehensively Bushrope
LegalTrademarks: Prehydration misapprehensively Bushrope
ProductName: Prehydration misapprehensively Bushrope
FileVersion: 7.92
ProductVersion: 7.92
InternalName: cactoid
OriginalFilename: cactoid.exe

Application.Barys.6305 (B) also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner1.24808
MicroWorld-eScanGen:Variant.Application.Barys.6305
FireEyeGeneric.mg.cdceebce3dc827b4
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.ek
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
K7GWEmailWorm ( 003c363a1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZevbaF.36802.im0@ae3R9ldi
VirITWorm.Win32.X-Autorun.BKSE
SymantecW32.Changeup!gen20
tehtrisGeneric.Malware
ESET-NOD32Win32/Pronny.CG
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SM01
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyTrojan.Win32.Jorik.Vobfus.fcga
BitDefenderGen:Variant.Application.Barys.6305
NANO-AntivirusTrojan.Win32.Autoruner1.cmxqir
AvastWin32:VBCrypt-BJA [Trj]
TencentMalware.Win32.Gencirc.10b556fe
EmsisoftGen:Variant.Application.Barys.6305 (B)
F-SecureTrojan.TR/Dropper.Gen
VIPREGen:Variant.Application.Barys.6305
TrendMicroWORM_VOBFUS.SM01
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-Y
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=75)
JiangminTrojan/Vbobf.b
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/VB.HC.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.997
MicrosoftWorm:Win32/Vobfus.GS
XcitiumTrojWare.Win32.Pronny.CG@4q65me
ArcabitTrojan.Application.Barys.D18A1
ZoneAlarmTrojan.Win32.Jorik.Vobfus.fcga
GDataGen:Variant.Application.Barys.6305
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R32692
VBA32Trojan.Vobfus
ALYacGen:Variant.Application.Barys.6305
TACHYONTrojan/W32.VB-Jorik.135168
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.Vobfus!1.99D5 (CLASSIC)
YandexTrojan.GenAsa!y9Ragz8q/QE
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.4380938.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VBCrypt-BJA [Trj]
Cybereasonmalicious.e3dc82
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.826893d3

How to remove Application.Barys.6305 (B)?

Application.Barys.6305 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment