Malware

Barys.11445 removal

Malware Removal

The Barys.11445 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.11445 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys

Related domains:

z.whorecord.xyz
a.tomx.xyz
directlinks.eu.pn

How to determine Barys.11445?


File Info:

crc32: 2F299C9F
md5: 71505b55049d448821f3e05c0dbc3708
name: 71505B55049D448821F3E05C0DBC3708.mlw
sha1: a7d5573cb0f4ede69ccba313f7cdfea8e46ee956
sha256: 9cca54e203d183be10960046466801793037f0e0f5999a49e66f9429f3549cd7
sha512: 847559f2acc8594a39a2921fda18bacafaee19bbf12a315d604c4d269274f8cd9d05c2dff65d8989ead01b95ac2ba9a7662faee100ff13226a688499ad841431
ssdeep: 12288:kqHOerqtSPQ5XWSXgd37Scs5HW+I48mmzUNKeBtF5cyT3PDYLjA3TUzzqNd8E1f:VHFqYP2mSd52InmziB75cYYLMAazI
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2012
Assembly Version: 1.0.0.0
InternalName: Window.exe
FileVersion: 1.0.0.0
ProductName: Window
ProductVersion: 1.0.0.0
FileDescription: Window
OriginalFilename: Window.exe

Barys.11445 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Winlock.7516
CynetMalicious (score: 99)
ALYacGen:Variant.Barys.11445
CylanceUnsafe
ZillyaTrojan.Injector.Win32.408848
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaRansom:Win32/Blocker.0720fbb3
Cybereasonmalicious.5049d4
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.AUT
APEXMalicious
AvastWin32:AutoRun-CXY [Trj]
ClamAVWin.Virus.Blocker-634
KasperskyTrojan-Ransom.Win32.Blocker.wwm
BitDefenderGen:Variant.Barys.11445
NANO-AntivirusTrojan.Win32.TrjGen.dklzqd
MicroWorld-eScanGen:Variant.Barys.11445
TencentWin32.Trojan.Blocker.Aexk
Ad-AwareGen:Variant.Barys.11445
SophosMal/Generic-S
ComodoMalware@#15xhky2axfban
BitDefenderThetaGen:NN.ZemsilF.34690.1q0@aa@9bfni
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.71505b55049d4488
EmsisoftGen:Variant.Barys.11445 (B)
JiangminTrojan/Blocker.afh
WebrootW32.Rogue.Gen
AviraTR/Dropper.MSIL.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.1E1786
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Fynloski.A
ArcabitTrojan.Barys.D2CB5
AegisLabTrojan.Win32.Generic.lYeJ
ZoneAlarmTrojan-Ransom.Win32.Blocker.wwm
GDataGen:Variant.Barys.11445
McAfeeArtemis!71505B55049D
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
PandaTrj/CI.A
RisingRansom.Blocker!8.12A (CLOUD)
YandexBackdoor.DarkKomet!3+7IAeeOKVI
IkarusTrojan.Win32.Spy
MaxSecureTrojan.Malware.121218.susgen
FortinetMSIL/Injector.RDV!tr
AVGWin32:AutoRun-CXY [Trj]
Paloaltogeneric.ml

How to remove Barys.11445?

Barys.11445 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment