Malware

Barys.130819 (file analysis)

Malware Removal

The Barys.130819 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.130819 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs

How to determine Barys.130819?


File Info:

crc32: 47619CED
md5: c6535119872b7226d7f98886be7da055
name: C6535119872B7226D7F98886BE7DA055.mlw
sha1: 7ce67875a160f2e7d56087d9eaba6505a3de822e
sha256: 4f53975d3d928a6a5f9abe635254b48f42ac119637f10d5237279288feb66c6f
sha512: 8904dde7de36e16d4f915666206828bc8d9cdb9da87496f2ec0c0ab58193889f16d402423aa0de1570cd9bbd5c3dcfd972ffbe3b5d9cf65685945a4a45800d2a
ssdeep: 3072:+o/PD3T4jP8YHKJduW/Q+vVQb6gQHWJDER6hdO:+o/rU/HqduW/b7iLhdO
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2021
FileVersion: 60.4400.10.900
ProductVersion: 60.4400.10.900
Translation: 0x0409 0x04b0

Barys.130819 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.CobaltStrike.4!c
ALYacGen:Variant.Barys.130819
CylanceUnsafe
SangforTrojan.Win32.CobaltStrike.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/CobaltStrike.2541c4a4
K7GWTrojan ( 0057a5b01 )
K7AntiVirusTrojan ( 0057a5b01 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.UQI
APEXMalicious
AvastWin32:HacktoolX-gen [Trj]
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Barys.130819
MicroWorld-eScanGen:Variant.Barys.130819
Ad-AwareGen:Variant.Barys.130819
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZedlaF.34050.hC8@ae2RbCei
McAfee-GW-EditionRDN/Generic PUP.z
FireEyeGen:Variant.Barys.130819
EmsisoftGen:Variant.Barys.130819 (B)
JiangminTrojan.Cometer.bvt
AviraTR/Agent.jwvfh
MicrosoftTrojan:Win32/Glupteba!ml
GDataGen:Variant.Barys.130819
AhnLab-V3Trojan/Win.Generic.C4462347
McAfeeRDN/Generic PUP.z
MAXmalware (ai score=85)
MalwarebytesTrojan.Agent
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H0CGS21
YandexTrojan.CobaltStrike!FaRhqDCykqc
IkarusTrojan.Win32.Agent
FortinetW32/CobaltStrike.UQI!tr
AVGWin32:HacktoolX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/HackTool.CobaltStrike.HgkASZQA

How to remove Barys.130819?

Barys.130819 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment