Malware

Barys.1549 removal instruction

Malware Removal

The Barys.1549 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.1549 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Malay (Malaysia)
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.cerdanya-hobbies.es

How to determine Barys.1549?


File Info:

crc32: 263D9DBB
md5: 754a33d8fe5019c18733131b6e27bd8a
name: 754A33D8FE5019C18733131B6E27BD8A.mlw
sha1: 5847a561f9ffe0b283fa4b1bc50196701ac59d59
sha256: 3e56f76611930bd9301c77cb2cc6a95844f692b18bbf3bc76da9d832770aa989
sha512: 43eb15d2981dce9179aab22b893baa9dc69c9f940e56b4bbf73ad0efbefe47bbd5a88aeb6e2d9370955597f301839d35f0c6bdec560772107f202fcb0fc9748a
ssdeep: 24576:Y0aMBgJEdCKGi7S6wKGi7S6aK/ldhHXTkaV7I2WDUKA7WRVT:Y0aMqJTKHwKHtHAaV7fiUKA7QVT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Julian Seward
FileDescription: Bzip2: file compressor; Complete package, except sources
FileVersion: 1.0.5.0
Comments: This installation was built with Inno Setup.
CompanyName: GnuWin32
Translation: 0x0409 0x04e4

Barys.1549 also known as:

K7AntiVirusTrojan ( 0055e3ef1 )
LionicTrojan.Win32.Aura.j!c
DrWebTrojan.Encoder.2667
CAT-QuickHealTrojan.VBCrypt.MF.2915
ALYacGen:Variant.Barys.1549
CylanceUnsafe
ZillyaTrojan.Aura.Win32.217
AlibabaRansom:Win32/Filecoder.075d3843
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.8fe501
SymantecRansom.TeslaCrypt
ESET-NOD32Win32/Filecoder.NFQ
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Aura.ake
BitDefenderGen:Variant.Barys.1549
NANO-AntivirusTrojan.Win32.Aura.eglfmk
MicroWorld-eScanGen:Variant.Barys.1549
TencentWin32.Trojan.Aura.Agbi
Ad-AwareGen:Variant.Barys.1549
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGen:Variant.Barys.1549
EmsisoftGen:Variant.Barys.1549 (B)
JiangminTrojan.Aura.ev
WebrootW32.Aura.ake
Antiy-AVLTrojan/Generic.ASMalwS.1AB257D
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Pottieq.A
ArcabitTrojan.Barys.D60D
GDataGen:Variant.Barys.1549
McAfeeArtemis!754A33D8FE50
MAXmalware (ai score=100)
VBA32Hoax.Aura
PandaTrj/CI.A
YandexTrojan.Aura!oYUS9RywSb0
IkarusTrojan.Win32.Filecoder
FortinetW32/Filecoder.NFQ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Barys.1549?

Barys.1549 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment