Malware

Barys.1435 removal guide

Malware Removal

The Barys.1435 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.1435 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Deletes executed files from disk
  • Attempts to disable Windows Defender
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Barys.1435?


File Info:

name: 8EED3C51330A90AE82EA.mlw
path: /opt/CAPEv2/storage/binaries/ad6260bb33b04bb2c628810f84cbfe9672d746d35595c3833f84683f1e69ac9e
crc32: 1F123556
md5: 8eed3c51330a90ae82eaebd297f14760
sha1: e51ae52c0c3eb4d8585bec3ac87f358a1ed3cfef
sha256: ad6260bb33b04bb2c628810f84cbfe9672d746d35595c3833f84683f1e69ac9e
sha512: 0bd7ac493ec7198a473475d77603cc336756218fac430d2d86bf7cdcc6a12f5268fb50917a024f30e7e236d014057eb78fc7133b53abca702abde9bc5dc630f5
ssdeep: 98304:Z3PjIqL7F19nHnfgjQ2ZzZo0OcvcCL2KGB9Cb/hne2:Z/319nYjQKz2cECLm9CTv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1520633CA43AE9B29EBC46D70C83FA391B4356CDDA4E9244E60551D00BE578EC7E6C84F
sha3_384: 669b095cf165596eb56d12c4bd0230516badb86e850a63aad32fa92e9bbb82898989b7cbf9dea10661159cff3e3bc05d
ep_bytes: a1d4f05d002bc703c74183ec04a39ef1
timestamp: 2012-03-09 11:03:03

Version Info:

0: [No Data]

Barys.1435 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.1435
FireEyeGeneric.mg.8eed3c51330a90ae
CAT-QuickHealWorm.Gamarue.B
SkyhighFakeAV-Rena.cw
McAfeeFakeAV-Rena.cw
ZillyaTrojan.Kryptik.Win32.846466
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00530c281 )
AlibabaVirTool:Win32/Obfuscator.925b04f1
K7GWTrojan ( 00530c281 )
Cybereasonmalicious.c0c3eb
ArcabitTrojan.Barys.D59B
BitDefenderThetaGen:NN.ZexaF.36744.Wx1@a8DnZlm
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.ACFL
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.1435
NANO-AntivirusTrojan.Win32.Kryptik.ldyag
SUPERAntiSpywareTrojan.Agent/Gen-FraudScan[Prod]
AvastWin32:FakeAlert-CEJ [Trj]
SophosML/PE-A
F-SecureTrojan.TR/Crypt.EPACK.Gen8
DrWebTrojan.Fakealert
VIPREGen:Variant.Barys.1435
EmsisoftGen:Variant.Barys.1435 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Rogue.Gen
GoogleDetected
AviraTR/Crypt.EPACK.Gen8
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Trojan.Generic.a
XcitiumTrojWare.Win32.Kryptik.ACF@4ogmlg
MicrosoftRogue:Win32/FakeRean
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Barys.1435
VaristW32/FakeAlert.ADQ.gen!Eldorado
AhnLab-V3Trojan/Win32.Yakes.R22095
ALYacGen:Variant.Barys.1435
MAXmalware (ai score=99)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Generic@AI.90 (RDML:kZp2Donkf9swl71ZUUld5g)
YandexTrojan.Kryptik!3PU4i+WHinA
IkarusPacker.Win32.Katusha
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/Yakes.W!tr
AVGWin32:FakeAlert-CEJ [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Barys.1435?

Barys.1435 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment