Malware

What is “Barys.1474”?

Malware Removal

The Barys.1474 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.1474 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Spanish (Modern)
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine Barys.1474?


File Info:

crc32: 540D4C35
md5: 599ea30947837a28f45d1ecc9000608f
name: 599EA30947837A28F45D1ECC9000608F.mlw
sha1: e12d7d6e655fcd59f5fb7c1d8a275c86a709620e
sha256: 6ea5da8de377d7e0a224d9d2317e2f27265c33abb135dceb125793b9e2ff737d
sha512: d50a7f1c36a97ff39c1d06d38b1a60e1b78f1b20e64aa70bf97e400983b0723b94050e71d87d7df5efda8d74fca53e2315d4045d041ab161891bf325fe84567b
ssdeep: 6144:LqWod4HqHXzhst63bpkEK4SCqjytGLnVW5GJZ2tNYLj8Mfsa5zhhx:LqWod4YXNam8VzYKj86sadhhx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Barys.1474 also known as:

K7AntiVirusPassword-Stealer ( 0055e3dc1 )
LionicTrojan.Win32.Dybalom.liJy
DrWebTrojan.PWS.Dybalom
CynetMalicious (score: 100)
ALYacGen:Variant.Barys.1474
CylanceUnsafe
ZillyaTrojan.Dybalom.Win32.5566
AlibabaTrojanPSW:Win32/Fignotok.b9f51e01
K7GWPassword-Stealer ( 0055e3dc1 )
Cybereasonmalicious.947837
CyrenW32/Fignotok.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.Fignotok.B
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastFileRepMetagen [Malware]
ClamAVWin.Trojan.Manbat-6915473-0
KasperskyTrojan-PSW.Win32.Dybalom.bkn
BitDefenderGen:Variant.Barys.1474
NANO-AntivirusTrojan.Win32.Dybalom.efydl
MicroWorld-eScanGen:Variant.Barys.1474
TencentWin32.Init.QQRob.bhyk
Ad-AwareGen:Variant.Barys.1474
SophosMal/PWS-FB
ComodoTrojWare.Win32.PSW.Dybalom.~FAT@1v5v1y
BitDefenderThetaGen:NN.ZexaF.34142.uyWaaWW7wRn
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.VirRansom.fc
FireEyeGeneric.mg.599ea30947837a28
EmsisoftGen:Variant.Barys.1474 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PSW.Dybalom.bhp
WebrootW32.Malware.Gen
AviraTR/Spy.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2409D3
KingsoftWin32.PSWTroj.Dybalom.(kcloud)
GDataGen:Variant.Barys.1474
TACHYONTrojan-Spy/W32.KeyLogger.341504.B
AhnLab-V3Trojan/Win32.Dybalom.C99391
McAfeeArtemis!599EA3094783
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Dybalom
MalwarebytesGeneric.Trojan.Dropper.DDS
PandaTrj/CI.A
YandexTrojan.PWS.Dybalom!6KIiT/1kU64
IkarusTrojan-PWS.Win32.Fignotok
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Dybalom.B!tr.pws
AVGFileRepMetagen [Malware]

How to remove Barys.1474?

Barys.1474 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment