Malware

Barys.2014 removal guide

Malware Removal

The Barys.2014 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.2014 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Anomalous binary characteristics

How to determine Barys.2014?


File Info:

name: 75A703059053EFB81220.mlw
path: /opt/CAPEv2/storage/binaries/2db62cc6d300d7b4ab03a70d6e6724054058acbbf6ee6047c32c4f7deb0900cf
crc32: 2E462DFD
md5: 75a703059053efb81220594bd9bf4c8e
sha1: 9289328e7513171b40ad51101e0091c79cacc9df
sha256: 2db62cc6d300d7b4ab03a70d6e6724054058acbbf6ee6047c32c4f7deb0900cf
sha512: 7cc7c25cd7d74ddc4b1ca180050fe3fa98f48e7a5e08ffa3d85b56e8c19cd83ed5a595560787fdae30fe6faf5e81d0f7185696d2357691887630e6caae537598
ssdeep: 768:JupZtHFTf1DBfP1IDZQxEmPu/pBl980O3XBKw+EUO5uy5R7:op7Hdf1DFdIDZyRQQJnBLX9v
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19F436C22B55D8632F24887B70A6297F299197D74DE416F2B395AFF2C3D342839E91303
sha3_384: 29aee3bad7226555349a187d03b0756847cdc41565e043c5c4dc1979ad1015c4790aa0eb056dc45aec89462277afd7bb
ep_bytes: 6844844000e8451e0000757365723332
timestamp: 2008-08-14 11:14:58

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Le!Tj0 CoDeR
ProductName: Project1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: You Stub
OriginalFilename: You Stub.exe

Barys.2014 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Blocker.j!c
MicroWorld-eScanGen:Variant.Barys.2014
FireEyeGeneric.mg.75a703059053efb8
McAfeeGeneric Malware.ja
CylanceUnsafe
ZillyaBackdoor.Poison.Win32.9722
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 0055e3df1 )
AlibabaRansom:Win32/Blocker.b270c34a
K7GWTrojan ( 0055e3df1 )
Cybereasonmalicious.59053e
CyrenW32/Heuristic-162!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.VB.NFZ
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.hghp
BitDefenderGen:Variant.Barys.2014
NANO-AntivirusTrojan.Win32.Poison.jhgi
APEXMalicious
Ad-AwareGen:Variant.Barys.2014
EmsisoftGen:Variant.Barys.2014 (B)
ComodoBackdoor@#o57cfqatm6ip
DrWebTrojan.MulDrop.28816
VIPREGen:Variant.Barys.2014
SophosML/PE-A + Mal/Packer
IkarusTrojan-Dropper.Win32.VB
JiangminBackdoor/PoisonIvy.bhz
WebrootVir.Tool.Gen
AviraHEUR/AGEN.1226412
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.77
KingsoftWin32.Hack.Poison.i.(kcloud)
ArcabitTrojan.Barys.D7DE
ViRobotBackdoor.Win32.Poison.57344
GDataGen:Variant.Barys.2014
GoogleDetected
VBA32Malware-Cryptor.VB.gen.1
ALYacGen:Variant.Barys.2014
TACHYONBackdoor/W32.Poison.57344
MalwarebytesMalware.Heuristic.1003
AvastWin32:VB-PPV [Drp]
TencentWin32.Trojan.Blocker.Uwhl
SentinelOneStatic AI – Malicious PE
FortinetW32/BackDoor.IRO!tr.bdr
AVGWin32:VB-PPV [Drp]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Barys.2014?

Barys.2014 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment