Malware

Barys.161085 removal guide

Malware Removal

The Barys.161085 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.161085 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Barys.161085?


File Info:

name: 82F440BA534011897F47.mlw
path: /opt/CAPEv2/storage/binaries/e851c123a837f4c3056b060f36be0baef6f16e32fcfb8264a98aeab7ac9f3a92
crc32: B58399D7
md5: 82f440ba534011897f470bc78b69e6e3
sha1: 0168840a9080d8f25556770084211f291d3d02a7
sha256: e851c123a837f4c3056b060f36be0baef6f16e32fcfb8264a98aeab7ac9f3a92
sha512: 5b3ae3e9d954dbe50948c1c251f9cf711528b7d1e505c34e8d991d809fc2d6aad198657e3a7cde110a4aed51e6df70e765b8d0b3631272f1151792f34161dd7b
ssdeep: 12288:/geFWgC2QbkLGcZtTqsWiW9Bzt6dBYcGalZC3kzvI8Bbrl6oXJUsJWey4/7/VuVj:PQ3Jb6aNl6EcGSC3ull55nWe3Vu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DBF42300A7D1C38BC953E9B02057E7E7B775FD4564868A4BE28C24EA6DC464ECF886B1
sha3_384: 1a50ab9e83aa5abbd5efc3c5222d4b2ce02d36f987aaf84892e49c571527bca9eba06f4b8937799beb82bf8e08f275b4
ep_bytes: 680b435e00681a435e00c3cee90a0000
timestamp: 2011-12-01 16:00:52

Version Info:

0: [No Data]

Barys.161085 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.161085
FireEyeGeneric.mg.82f440ba53401189
ALYacGen:Variant.Barys.161085
CylanceUnsafe
VIPRETrojan-Dropper.Win32.Resdro.b (v) (not malicious)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052c8a31 )
AlibabaRiskWare:Win32/FlyStudio.b6fa567f
K7GWTrojan ( 0052c8a31 )
Cybereasonmalicious.a53401
BitDefenderThetaGen:NN.ZexaF.34182.WuqaaencLFb
VirITTrojan.Win32.Agent.BWB
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.Packed.V potentially unwanted
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Barys.161085
NANO-AntivirusTrojan.Win32.Crypted.dfqhhg
AvastWin32:Malware-gen
TencentWin32.Trojan.Crypt.Ecam
EmsisoftGen:Variant.Barys.161085 (B)
ComodoMalware@#3i2k783pchduy
DrWebBackDoor.BlackHole.15415
McAfee-GW-EditionBehavesLike.Win32.Backdoor.bc
SentinelOneStatic AI – Malicious PE
SophosGeneric ML PUA (PUA)
APEXMalicious
JiangminRiskTool.IMEStartup.ahe
WebrootW32.Trojan.Gen
AviraTR/Crypt.CFI.Gen
MicrosoftPWS:Win32/Zbot!ml
ZoneAlarmnot-a-virus:RiskTool.Win32.IMEStartup.a
GDataGen:Variant.Barys.161085
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.HDC.C152462
McAfeeBackDoor-EXZ
MAXmalware (ai score=88)
VBA32HackTool.Sniffer.WpePro
YandexTrojan.GenAsa!MlIHk/Ow0VY
IkarusBackdoor.Win32.Zegost
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Filecoder.FV!tr.ransom
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Barys.161085?

Barys.161085 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment