Malware

Barys.104231 malicious file

Malware Removal

The Barys.104231 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.104231 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Creates known SpyNet mutexes and/or registry changes.
  • Anomalous binary characteristics

How to determine Barys.104231?


File Info:

crc32: 9835DDF6
md5: 7adf46a9b885a90c110e48adf356239d
name: 7ADF46A9B885A90C110E48ADF356239D.mlw
sha1: 49ef62fe91b16d76cb8fcab551e093975018fce9
sha256: 6e742c87a613d468e89fde31cc976ec37d0094b48ff9b23a028688cf6f0c849f
sha512: 8631ac2faf66d28042aeb14f6cb5894b70b97dff6909afc7107369fa973ebbcd5966e3ddb66fac9ff5d42f06c5ecfdbf7354bd8eeb89d41917046ebe168ff3d2
ssdeep: 6144:ExBhllO9G2ofy/XbUCdpUqQ4gHNpIT84YayKWwJXDAsnsFKwF:ExBwZpUq+HNpB45VWwwF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: xa3vxf5x153x153xe6Oxb1x17exdazs1x1533BBOx153B
InternalName: limpo
FileVersion: 7.01.0022
CompanyName: x17eKj7rtxa3x17enx153BxecHx2122svxdaxf5jx153
LegalTrademarks: zx153xabzOxf53qsx153wxf5Zx17ex153xdexf5Mx17eh
Comments: xde2QIBwxecxb18Enxf2axe8x153x153sxc1mz
ProductName: 4xkx153xdaxb1ux1530sxf2xdaFHkx153Bxe8Hxde
ProductVersion: 7.01.0022
FileDescription: x2122kyVdx17eHzx192zyox153xf21xdeDQDz
OriginalFilename: limpo.exe

Barys.104231 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3991 )
Elasticmalicious (high confidence)
DrWebTrojan.KillFiles.16371
CynetMalicious (score: 100)
CAT-QuickHealTrojan.VBCrypt.MF.82
ALYacGen:Variant.Barys.104231
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Injector.532f20f3
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.9b885a
CyrenW32/A-c13828ea!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.BGXC
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.DarkKomet-9204913-0
KasperskyTrojan.Win32.Agent.nesavs
BitDefenderGen:Variant.Barys.104231
NANO-AntivirusTrojan.Win32.KillFiles.fmhjim
MicroWorld-eScanGen:Variant.Barys.104231
TencentMalware.Win32.Gencirc.10b0f21a
Ad-AwareGen:Variant.Barys.104231
SophosMal/Generic-S
ComodoTrojWare.Win32.VB.DRPF@5hzrzj
BitDefenderThetaGen:NN.ZevbaF.34686.in3@aSlNzUci
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXAE-LP!7ADF46A9B885
FireEyeGeneric.mg.7adf46a9b885a90c
EmsisoftGen:Variant.Barys.104231 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agent.adsf
AviraTR/Symmi.olaks
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Barys.104231
TACHYONTrojan/W32.VB-Agent.1188406
AhnLab-V3Trojan/Win32.Symmi.R139961
McAfeeGenericRXAE-LP!7ADF46A9B885
MAXmalware (ai score=88)
VBA32Trojan.Agent
MalwarebytesTrojan.Injector
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R014C0PDR21
RisingWorm.Rebhip!8.B31 (CLOUD)
YandexTrojan.Injector!iFb8FsAUYSc
IkarusTrojan.Win32.Inject
FortinetW32/Injector.BLMO!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Barys.104231?

Barys.104231 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment