Malware

Should I remove “Barys.1579”?

Malware Removal

The Barys.1579 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.1579 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Barys.1579?


File Info:

name: EBF84CF41BF573EB3764.mlw
path: /opt/CAPEv2/storage/binaries/f6a2ff2ce60c625aab9cdc8ce0f788885a40df41b9ab58e3a845f66b047f90c3
crc32: 2C6FF372
md5: ebf84cf41bf573eb37641f67ea70130d
sha1: c258c5a3366b38d20b8c912e621318ae3ed7bf2b
sha256: f6a2ff2ce60c625aab9cdc8ce0f788885a40df41b9ab58e3a845f66b047f90c3
sha512: f5d8254789c4e55aee79f2f66359eff710d7ef6cd893846854a9755c64bd33dc4013f54800f24f0e5195d580c26bf549405131e99c2e8275f1e8ee7441e15589
ssdeep: 6144:XbzIl/NtOVii9Nv9M58w4seCwO5guVNg875koS5mY:XbzIl/bri9NvDwne0GugCyoSwY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B8141279EB519505F57F933FD9FA6C08AC60F09DEE618F0E00E9850D6CD2BA41E24B86
sha3_384: d550b960e00252429ed2cbc3eefc317153402d30d7dd68a96330d5743485a30ca3e023c76084776ec647f049ca32b182
ep_bytes: 60be006042008dbe00b0fdff5789e58d
timestamp: 2011-04-11 14:01:21

Version Info:

CompanyName: Quick Heal Technologies (P) Ltd.
FileDescription: Quick Heal AntiMalware
FileVersion: 6.0.0.1
InternalName: asmain.exe
LegalCopyright: © Quick Heal Technologies (P) Ltd. All rights reserved.
OriginalFilename: asmain.exe
ProductName: Quick Heal AntiVirus
ProductVersion: 13.00
Translation: 0x0409 0x04e4

Barys.1579 also known as:

DrWebTrojan.PWS.Panda.655
CynetMalicious (score: 100)
FireEyeGeneric.mg.ebf84cf41bf573eb
CAT-QuickHealTrojanBNK.Zbot.mue
McAfeePWS-Zbot.gen.qz
VIPRETrojan.Win32.Reveto.D (v)
SangforSpyware.Win32.Zbot.YW
K7AntiVirusPassword-Stealer ( 003c6e581 )
AlibabaTrojanSpy:Win32/SmokeLdr.ce6807ad
K7GWPassword-Stealer ( 003c6e581 )
CrowdStrikewin/malicious_confidence_70% (W)
ArcabitTrojan.Barys.D62B
BitDefenderThetaGen:NN.ZexaF.34212.mm1@aupxmfli
SymantecPacked.Generic.350
ESET-NOD32Win32/Spy.Zbot.YW
TrendMicro-HouseCallTROJ_FRS.0NA103BL20
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.1579
NANO-AntivirusTrojan.Win32.Panda.fmhcra
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
MicroWorld-eScanGen:Variant.Barys.1579
AvastFileRepMalware
TencentWin32.Trojan.Falsesign.Apcy
Ad-AwareGen:Variant.Barys.1579
EmsisoftGen:Variant.Barys.1579 (B)
ComodoMalware@#1vrai5s0x3r7l
ZillyaTrojan.Menti.Win32.27240
TrendMicroTROJ_FRS.0NA103BL20
McAfee-GW-EditionPWS-Zbot.gen.qz
SophosMal/Generic-S + Mal/Zbot-EZ
IkarusTrojan.Crypt
JiangminTrojan/Menti.qrv
eGambitGeneric.Malware
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftPWS:Win32/Zbot!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Barys.1579
SentinelOneStatic AI – Malicious PE
AhnLab-V3Win-Trojan/Zbot.202320
Acronissuspicious
VBA32Malware-Cryptor.ImgChk
ALYacGen:Variant.Barys.1579
CylanceUnsafe
APEXMalicious
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojanSpy.Zbot!cKqVwbja9vQ
MAXmalware (ai score=100)
MaxSecureTrojan.Malware.3571771.susgen
FortinetW32/Kryptik.ABC!tr
WebrootW32.Infostealer.Zeus
AVGFileRepMalware
Cybereasonmalicious.41bf57
PandaGeneric Malware

How to remove Barys.1579?

Barys.1579 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment