Malware

Barys.104667 removal tips

Malware Removal

The Barys.104667 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.104667 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (8 unique times)
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

Related domains:

hubvera.ac.ug
ddlakava.ac.ug
telete.in
apps.identrust.com
mazoyer.ac.ug
mazooyaar.ac.ug
bit.do
sergui.ac.ug
mastitisa.ac.ug
rebrand.ly
ludivineemery.ac.ug
danwisha.ac.ug
tinyurl.com
kode.ac.ug
kodekode.ac.ug
tuekisa.ac.ug
partadino.ac.ug
markinda.xyz
markinda.top
mckawwrsa.ac.ug
ludivin.ac.ug
wishamag.ac.ug
cointra.ac.ug
muylove.ac.ug
partiad.top
partiad.xyz

How to determine Barys.104667?


File Info:

crc32: EF08327F
md5: a961693763f627dc8b4c030f69ce751d
name: A961693763F627DC8B4C030F69CE751D.mlw
sha1: a676ee57ff0eae3a73b370196ac3ad51fcb45f8f
sha256: aec46d1dcd8856f0fafccca65665fb836cf4d031157414fc11d08af9923e9545
sha512: 634f46969c2ec5871fc6246dd3291dd617caaa4b91ca666b99c3def8ab16f5ce4fc951089aef32f57910c33460965fd94534cedd9cdeefa7e7d30af4275a79a3
ssdeep: 12288:qvq0sFeXeVzXOYVLvuWOOJ1iFjbrp4NplXz2U3IpeUa6URfQ4AmFPTbFNbD:qvq01XMOYCiTipbtsp6IQ4AET5Nn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Barys.104667 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00581c7f1 )
LionicTrojan.Win32.Chapak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.62490
CynetMalicious (score: 100)
ALYacGen:Variant.Barys.104667
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:Win32/Chapak.b2c59f55
K7GWTrojan ( 00581c7f1 )
Cybereasonmalicious.763f62
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EQAA
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Barys-9890423-0
KasperskyTrojan.Win32.Chapak.fazg
BitDefenderGen:Variant.Barys.104667
MicroWorld-eScanGen:Variant.Barys.104667
Ad-AwareGen:Variant.Barys.104667
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZevbaF.34142.XmW@aGtt43b
McAfee-GW-EditionBehavesLike.Win32.Trojan.bc
FireEyeGeneric.mg.a961693763f627dc
EmsisoftGen:Variant.Barys.104667 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Remcos.ARK!MTB
GDataGen:Variant.Barys.104667
AhnLab-V3Trojan/Win.Remcos.R439799
Acronissuspicious
McAfeeGenericRXPU-QT!A961693763F6
MAXmalware (ai score=83)
VBA32BScope.TrojanPSW.Stelega
MalwarebytesMalware.AI.4145333283
PandaTrj/CI.A
RisingTrojan.Injector!1.C6AF (CLASSIC)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FJIT!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Barys.104667?

Barys.104667 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment