Malware

What is “Barys.2475”?

Malware Removal

The Barys.2475 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.2475 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Barys.2475?


File Info:

name: 4746A1E7753DCE32945F.mlw
path: /opt/CAPEv2/storage/binaries/d2122e92611cddac23f99493015ec3c02ea35cac0523c3c94047f781938adfe6
crc32: A47A2C12
md5: 4746a1e7753dce32945f3c02119a8017
sha1: 0aa51031b9b4d34d87a1c0170f025715290bb7af
sha256: d2122e92611cddac23f99493015ec3c02ea35cac0523c3c94047f781938adfe6
sha512: 9ad40d11fa9df4a6ad2446d68c4ab821eabec3010d5fdfd796de0b5190ded26bf7dde2076a5a63112de63e4e86c6ee2261c654fa9b2ccabadb01ff2b3da45b3f
ssdeep: 6144:oJw0/YHVK/zGKF8Vo0uebQVC0e9f9Ifjkk11zWj1xsX4YC:2ToVvK+VopVGf96jWj1CXtC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A2402F374B544A0E07804BD1BEAB71A4B7DEE9A16648A3727E830E13CF085175A35DB
sha3_384: 93afc88436334e3d1b3a3cd0ff79a4e3fc55161abdf21f8f6e897b5b8932126475617f295ea4c7535d9f749595fa3eca
ep_bytes: 558bec83ec30535756ff0dbb0041006a
timestamp: 2004-06-11 19:45:18

Version Info:

FileDescription: G Data InternetSecurity Scheduler Service
LegalCopyright: G Data Software AG. Все права защищены.
InternalName: AVK Service
ProductName: G Data InternetSecurity
CompanyName: WestByte
FileVersion: 2.0.8.2
ProductVersion: 6.2.5.8
Translation: 0x0409 0x0000

Barys.2475 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zbot.l!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Barys.2475
ClamAVWin.Trojan.Zbot-22803
FireEyeGeneric.mg.4746a1e7753dce32
ALYacGen:Variant.Barys.2475
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.60219
SangforSpyware.Win32.Zbot.AAO
K7AntiVirusSpyware ( 0055e3db1 )
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.7753dc
VirITTrojan.Win32.Generic.CFGX
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Zbot.AAO
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.2475
NANO-AntivirusTrojan.Win32.Zbot.rgmyk
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Zbot-OJC [Trj]
TencentMalware.Win32.Gencirc.10c463fa
Ad-AwareGen:Variant.Barys.2475
EmsisoftGen:Variant.Barys.2475 (B)
ComodoTrojWare.Win32.Kryptik.DTLG@4roqbq
DrWebTrojan.Proxy.24369
VIPREGen:Variant.Barys.2475
McAfee-GW-EditionPWS-Zbot.gen.avr
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.2475
JiangminTrojan/Generic.abqzp
WebrootW32.Rogue.Gen
AviraTR/Crypt.XPACK.Gen8
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.31
MicrosoftPWS:Win32/Zbot
GoogleDetected
McAfeePWS-Zbot.gen.avr
VBA32TrojanSpy.Zbot
RisingMalware.Zbot!8.E95E (TFE:1:AWtlsnYE5jB)
YandexTrojan.GenAsa!6SufJoGDI34
IkarusWorm.Win32.Cridex
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Shiz.NCF!tr
BitDefenderThetaGen:NN.ZexaF.34606.nK1@aeipgZii
AVGWin32:Zbot-OJC [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Barys.2475?

Barys.2475 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment