Malware

Barys.118842 (file analysis)

Malware Removal

The Barys.118842 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.118842 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects the presence of Wine emulator via registry key
  • Emumerates physical drives
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Barys.118842?


File Info:

name: A85F90F07DD9E8AAB51C.mlw
path: /opt/CAPEv2/storage/binaries/7e7e709653948525de45868ce3d9f06901acb93c3329eb9a6f305009eb118057
crc32: 0125F3CE
md5: a85f90f07dd9e8aab51c65d8287ec6be
sha1: fbdece1f34820f3085e407ee6ef99f1862b9166f
sha256: 7e7e709653948525de45868ce3d9f06901acb93c3329eb9a6f305009eb118057
sha512: 2d2e89f55582cf13f9c45318ce2d1ab639f7051b80f47901d1fb89d2aec1eb285f88ce6b3ebde2222302c5a332e6c6643a84168fe2eaa427e7ac300eb8771089
ssdeep: 49152:qmLe1rVdN3pyabcm/FmKf39TB08AQBwGl1IrwFHDgvPGmt5XtVwKF:HLe1rfPcm9ff3zsQBwGlK0FHwPGmtvt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T168D5DE21EA83C831EB691174C5B74AF15872BD68D2F1518B3EBCBE2E3B741A18536F11
sha3_384: a7062012b0f38377c27c9437f8d0b7092a5ea5bf20b236f776b4811f996a80554d97dc038a52987bbc4fe27f4c87c44c
ep_bytes: 558bec6aff6850835f0068584c5f0064
timestamp: 2019-02-19 18:20:22

Version Info:

FileVersion: 14.0.1.39989
OriginalFilename: setup.exe
ProductVersion: 14.0.1.39989
Translation: 0x0409 0x04b0

Barys.118842 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ekstak.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Barys.118842
FireEyeGeneric.mg.a85f90f07dd9e8aa
CAT-QuickHealTrojan.Inject .S5450935
SkyhighPacked-FME!A85F90F07DD9
ALYacTrojan.Ekstak.gen
Cylanceunsafe
VIPREGen:Variant.Barys.118842
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 00548af91 )
BitDefenderGen:Variant.Barys.118842
K7GWTrojan ( 005482b31 )
Cybereasonmalicious.f34820
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GPWB
APEXMalicious
KasperskyTrojan.Win32.Ekstak.nobf
AlibabaTrojan:Win32/InstClick.190308
NANO-AntivirusTrojan.Win32.InstallCube.fnfoie
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
EmsisoftGen:Variant.Barys.118842 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.InstallCube.3908
ZillyaTrojan.Ekstak.Win32.23011
TrendMicroTROJ_FRS.0NA103C320
SophosMal/Generic-S
IkarusPUA.ICLoader
MAXmalware (ai score=96)
JiangminTrojan.Ekstak.yfy
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/Icloader.CRFE-6851
Antiy-AVLGrayWare/Win32.Kryptik.a
MicrosoftTrojan:Win32/CryptInject
XcitiumApplication.Win32.ICLoader.GS@84429a
ArcabitTrojan.Barys.D1D03A
ZoneAlarmTrojan.Win32.Ekstak.nobf
GDataGen:Variant.Barys.118842
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.Bundler.R256084
McAfeePacked-FME!A85F90F07DD9
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Ekstak
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FRS.0NA103C320
TencentMalware.Win32.Gencirc.10bcdf65
YandexTrojan.GenAsa!1Y4Hwa2ZHp4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.74142779.susgen
FortinetW32/Kryptik.GNOG!tr
BitDefenderThetaGen:NN.ZexaF.36792.4s0@ayFhYMdi
AVGWin32:ICLoader-X [Adw]
AvastWin32:ICLoader-X [Adw]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Barys.118842?

Barys.118842 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment