Malware

Should I remove “Barys.19590”?

Malware Removal

The Barys.19590 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.19590 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Sniffs keystrokes
  • Creates a copy of itself
  • Attempts to create or modify system certificates
  • Makes SMTP requests, possibly sending spam or exfiltrating data.

Related domains:

z.whorecord.xyz
smtp.gmail.com
a.tomx.xyz

How to determine Barys.19590?


File Info:

crc32: AEDE68E4
md5: 4e94d0b142f19aec33cf9ca8f321c831
name: 4E94D0B142F19AEC33CF9CA8F321C831.mlw
sha1: ae5ffde9226694f940558001f8a76a7872e399a4
sha256: 408d1e50f5bd678455494bc95458f8dc6c1f46ba4d1ec636c876c415f5c95584
sha512: bec56eb4128858f4c1e45ef9139a1b2a1688fa183c031e44aca90d76502e83ae5d482ca37f893f120c6947e57cde64e758272e95d146d4133bd01836e8eb9f62
ssdeep: 1536:Jo6QNd5nZSI8sNjyGaJRyx3HiNERfW4vcsq4tGBZYndtEyvxrmH++GPB/71afLx:+DZzH164ksB4MndPrb+GN1+YKC8sUxI
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: sJcAPqa
Assembly Version: 15.58.58.5
InternalName: v1nosc.exe
FileVersion: 8.18.95.45
CompanyName: bGivLfZnL
Comments: dOhSd
ProductName: AwaDpPFfeJbzYsd
ProductVersion: 8.18.95.45
FileDescription: rMIsL
OriginalFilename: v1nosc.exe

Barys.19590 also known as:

K7AntiVirusTrojan ( 004e06551 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader26.38804
CynetMalicious (score: 99)
ALYacGen:Variant.Barys.19590
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004e06551 )
Cybereasonmalicious.142f19
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.kytt
BitDefenderGen:Variant.Barys.19590
NANO-AntivirusTrojan.Win32.MultiPacked.fakyzr
MicroWorld-eScanGen:Variant.Barys.19590
TencentWin32.Trojan.Blocker.Pgnc
Ad-AwareGen:Variant.Barys.19590
SophosMal/Generic-S
ComodoMalware@#3vgtfmmgbrl4f
F-SecureTrojan.TR/Spy.Gen
BitDefenderThetaGen:NN.ZemsilF.34790.gm0@am77Dof
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
FireEyeGeneric.mg.4e94d0b142f19aec
EmsisoftGen:Variant.Barys.19590 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Spy.Gen
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Barys.D4C86
GDataGen:Variant.Barys.19590
McAfeeArtemis!4E94D0B142F1
MAXmalware (ai score=97)
PandaTrj/GdSda.A
YandexTrojan.Blocker!UvLErFSaOIo
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HwMAEpsA

How to remove Barys.19590?

Barys.19590 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment