Malware

Should I remove “Barys.18993”?

Malware Removal

The Barys.18993 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.18993 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Creates a copy of itself

How to determine Barys.18993?


File Info:

name: E9345875112F289B0597.mlw
path: /opt/CAPEv2/storage/binaries/47d4d62e04575ace2fd38950c56a59f7f2264549ecb0640809e93a5476862efc
crc32: 7F47B4A8
md5: e9345875112f289b0597181119ec0d17
sha1: 1977cccd4a590bf276c34d9db8ff224607b5a1f2
sha256: 47d4d62e04575ace2fd38950c56a59f7f2264549ecb0640809e93a5476862efc
sha512: 0ed634f27ba26880147605f79e8f7533b8da02c873231fb83d286d0ae11027b4286477c895c0c87e47d07c274c21eb83fe64fcb27a10c5ea5a8845c877cfd772
ssdeep: 768:vejbO/NbxS2BxU6MuSo/U/k/Y/0NrYlk+b4yZ//V5:vbhxSSjM8QqYmA7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C0F2E8097BDC402BE1ACEB314F63F64383B1EA776657C7AF0ED15CA8373A69409415A2
sha3_384: 999ed66e69b20dd7c527cfc6bd5d0ebd23022d89e54c5d7f1e207dd1b3a28f3f706a5334574943c8c6f94fcdcb7c6fec
ep_bytes: ff250020400000000000000000000000
timestamp: 2015-01-01 13:25:17

Version Info:

0: [No Data]

Barys.18993 also known as:

BkavW32.AIDetectNet.01
CynetMalicious (score: 99)
FireEyeGeneric.mg.e9345875112f289b
ALYacGen:Variant.Barys.18993
VIPREGen:Variant.Barys.18993
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.5112f2
VirITTrojan.Win32.Bladabindi.AQLG
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Bladabindi.CM
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Crypt.gen
BitDefenderGen:Variant.Barys.18993
NANO-AntivirusTrojan.Win32.Autoruner.ctqpfj
MicroWorld-eScanGen:Variant.Barys.18993
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Barys.18993
EmsisoftGen:Variant.Barys.18993 (B)
DrWebBackDoor.NJRat.421
McAfee-GW-EditionBehavesLike.Win32.Trojan.nm
Trapminemalicious.high.ml.score
SophosML/PE-A
IkarusBackdoor.NJRat
GDataGen:Variant.Barys.18993
JiangminTrojan.Pec0pudime.am
AviraHEUR/AGEN.1208283
Antiy-AVLTrojan/Generic.ASMalwS.3303
ArcabitTrojan.Barys.D4A31
ZoneAlarmHEUR:Trojan.MSIL.Crypt.gen
MicrosoftProgram:Win32/Wacapew.C!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Crypt.R336301
Acronissuspicious
McAfeeTrojan-FSHS!E9345875112F
MAXmalware (ai score=89)
CylanceUnsafe
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:TF8En2a/4iEgbzRx/w3qXA)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Generic.AP.99EB70!tr
BitDefenderThetaGen:NN.ZemsilF.34646.cmW@aeGn@0p
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Barys.18993?

Barys.18993 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment