Malware

What is “Barys.23660”?

Malware Removal

The Barys.23660 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.23660 virus can do?

  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Barys.23660?


File Info:

name: 2E82687E0458C7967585.mlw
path: /opt/CAPEv2/storage/binaries/4ef43db9a36fa5ecdc18dccd889c9d5438948aebd2cc3b4418dd717c875c0f12
crc32: FE2A5D0E
md5: 2e82687e0458c79675857aef415d0538
sha1: 0b4d98b22ed157178a8aa02cfed44d054c2ef6c1
sha256: 4ef43db9a36fa5ecdc18dccd889c9d5438948aebd2cc3b4418dd717c875c0f12
sha512: 9b9c31f94f8ea0467beffcd1f7d0dc8c65e37588bc8ce7adc47398374c82cd9dd7a027970610059ea0563118596e78f2f0a061fc6f80b5984e7419736f185050
ssdeep: 6144:uj9XCoSTCaJPKx5GiS3bkr9/vsJoDNP5msDrbkBpT2U2a:uJXCoCKx5Gl3e/QPpTrr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F3346CAC73D77B70D34A0674C69312258B388A2A83CBF3AF66470495F8C13E5F596993
sha3_384: 1ced2f9eea497d5f9b3dc2713c0b3e24f86cfcf320c9aa8dec860ef5edc550cca7c8a89884644eb4dd54c8bb39a2cda5
ep_bytes: ff250020400000000000000000000000
timestamp: 2013-11-20 04:58:06

Version Info:

0: [No Data]

Barys.23660 also known as:

MicroWorld-eScanGen:Variant.Barys.23660
FireEyeGeneric.mg.2e82687e0458c796
McAfeeArtemis!2E82687E0458
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Variant.Barys.23660
K7GWTrojan ( 700000121 )
Cybereasonmalicious.e0458c
BitDefenderThetaGen:NN.ZemsilF.34646.omW@a4ALJkd
CyrenW32/MSIL_Troj.WH.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Bladabindi.AR
BaiduMSIL.Backdoor.Bladabindi.a
APEXMalicious
ClamAVWin.Packed.Bladabindi-7086597-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Bladabindi.cnmyvm
CynetMalicious (score: 100)
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
Ad-AwareGen:Variant.Barys.23660
SophosML/PE-A
ComodoMalware@#lfpa51wqplmm
VIPREGen:Variant.Barys.23660
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Barys.23660 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.23660
JiangminTrojan/Refroso.cem
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2CD
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Barys.D5C6C
MicrosoftBackdoor:MSIL/Bladabindi.AJ
GoogleDetected
Acronissuspicious
ALYacGen:Variant.Barys.23660
MAXmalware (ai score=81)
PandaGeneric Malware
TencentWin32.Trojan.Generic.Nqil
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic!tr
AVGMSIL:GenMalicious-C [Trj]
AvastMSIL:GenMalicious-C [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Barys.23660?

Barys.23660 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment