Malware

What is “Barys.237529”?

Malware Removal

The Barys.237529 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.237529 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Barys.237529?


File Info:

name: EB3DFA2DE2BF15378325.mlw
path: /opt/CAPEv2/storage/binaries/f962f40f31ac91400d159bf86338be4a0f3d1cf40c6c24f63de2af3e1c13f7d9
crc32: 1D0AC501
md5: eb3dfa2de2bf153783256750615dd155
sha1: 6f1ea40cf569e8085b7764a474f6a8e57d974a5b
sha256: f962f40f31ac91400d159bf86338be4a0f3d1cf40c6c24f63de2af3e1c13f7d9
sha512: 76510d1a90281311b36b3239a41423f7df73fef2c436492ed193efe3379d7a9f8183a51b48df4652d0f93d9db06d9839603e39cc35544b327d54865a51f787d7
ssdeep: 1536:rVRkumVuYaBU8gRDGHPOGMmUbaxGAka+t/K9rCGaV9mw7Jqx8M+dzAb9QgRV5:BcVuYsa4UbaxqkCGaVD7JqfKAbGo5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BDF370AB7F752478F56856332DF782F207F2E44C4A0F42427E6C62256AEBE121D25B43
sha3_384: 8927685f4b174b6c659a207bbe2e987f9eaa3f3559ac1c71cb76a998308a6d3b16e01741074402097e63d5919018e129
ep_bytes: 6818124000e8f0ffffff000000000000
timestamp: 2012-04-18 19:57:50

Version Info:

0: [No Data]

Barys.237529 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.237529
FireEyeGeneric.mg.eb3dfa2de2bf1537
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.ct
McAfeeVBObfus.dv
MalwarebytesGeneric.Worm.AutoRun.DDS
VIPREGen:Variant.Barys.237529
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
BaiduWin32.Worm.Autorun.ad
VirITTrojan.Win32.Cryptor.F
SymantecW32.Changeup
ESET-NOD32Win32/AutoRun.VB.AUV
APEXMalicious
TrendMicro-HouseCallTSPY_VOBFUS_BK083CCC.TOMC
AvastWin32:VB-ACLE [Trj]
ClamAVWin.Trojan.Vobfus-58
KasperskyTrojan.Win32.VBKrypt.mbhp
BitDefenderGen:Variant.Barys.237529
NANO-AntivirusTrojan.Win32.VBKrypt.cqkxty
TencentTrojan.Win32.VB.tkf
EmsisoftGen:Variant.Barys.237529 (B)
GoogleDetected
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner1.15156
TrendMicroTSPY_VOBFUS_BK083CCC.TOMC
Trapminemalicious.high.ml.score
SophosMal/VBCheMan-J
IkarusTrojan.Win32.VB
JiangminTrojan/VBKrypt.hbdq
VaristW32/VB.FX.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus.EN
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Barys.D39FD9
ViRobotTrojan.Win32.A.VBKrypt.159744.APL
ZoneAlarmTrojan.Win32.VBKrypt.mbhp
GDataGen:Variant.Barys.237529
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R24436
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36804.jmW@a0BSvKn
ALYacGen:Variant.Barys.237529
TACHYONTrojan/W32.Agent.159744
VBA32SScope.Malware-Cryptor.VBCR.3042
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.Win32.Gnail.a (CLASSIC)
YandexTrojan.GenAsa!21jMssF5vgo
MAXmalware (ai score=89)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-ACLE [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.UnkAgent

How to remove Barys.237529?

Barys.237529 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment