Malware

Barys.2564 removal instruction

Malware Removal

The Barys.2564 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.2564 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Disables Interner Explorer creating a new process per tab, possibly for browser injection
  • Attempts to disable UAC
  • Anomalous binary characteristics

How to determine Barys.2564?


File Info:

name: 350B0A10DFB4356E1361.mlw
path: /opt/CAPEv2/storage/binaries/d07d08084ad05a746664048ec2578828c8c0851095a70583b64c018fe4fdbd1c
crc32: EB454634
md5: 350b0a10dfb4356e1361dc605f960ffc
sha1: 0724fb9aee05110a2506d38e12a3a2f1df5a28f0
sha256: d07d08084ad05a746664048ec2578828c8c0851095a70583b64c018fe4fdbd1c
sha512: c6702e8b0fabdbb63930113eda65c27b6b12b1e57374317500706209b90219fa1a0816d2e420d3bef9b87775a41c55e5e51960a02114f503fb6e3bfad131c639
ssdeep: 12288:fEhmGbdAyU+aaOMatQFryzWoAbhkAxX5Z3a:fEhmGbxtfOXQyWbCg5ha
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T132A4BE902CE65F8EF477A47197209D77986FBC60614232DA3224743437B6AE2DAED03D
sha3_384: 75ccab1f8ecbff013d33ef7fc899ac85d359f1aa35da490ef0302c6cbdb3c7f2b478deab846750615bd4cbd53e94bbe6
ep_bytes: 68f5fb4400e801000000c3c3df579cd0
timestamp: 2001-08-17 20:52:32

Version Info:

0: [No Data]

Barys.2564 also known as:

LionicTrojan.Win32.Homa.a!c
tehtrisGeneric.Malware
DrWebTrojan.Click.20169
MicroWorld-eScanGen:Variant.Barys.2564
FireEyeGeneric.mg.350b0a10dfb4356e
McAfeeGenericRXAA-AA!350B0A10DFB4
CylanceUnsafe
Sangfor[NTKRNL SECURE SUITE V0.1 -> NTKRNL SOFTWARE ! SIGN BY FLY]
K7AntiVirusTrojan-Downloader ( 002e302e1 )
K7GWTrojan-Downloader ( 002e302e1 )
Cybereasonmalicious.0dfb43
BitDefenderThetaGen:NN.ZexaF.34742.CiWaaaLfN@pG
VirITBackdoor.RBot.XY
CyrenW32/SuspPack.G.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Delf.QPL
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Downloader.Homa-9946150-0
KasperskyTrojan-Banker.Win32.BestaFera.ge
BitDefenderGen:Variant.Barys.2564
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
SUPERAntiSpywareTrojan.Agent/Gen-Banker
AvastWin32:Trojan-gen
TencentWin32.Trojan-Downloader.Homa.uch
Ad-AwareGen:Variant.Barys.2564
SophosML/PE-A + Mal/Banker-Z
ComodoTrojWare.Win32.PSW.Ldpinch.~NNT@1op6ij
VIPREGen:Variant.Barys.2564
TrendMicroTROJ_GEN.R03BC0RFP22
McAfee-GW-EditionBehavesLike.Win32.VirRansom.gc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Barys.2564 (B)
IkarusTrojan-Downloader.Win32.Homa
GDataGen:Variant.Barys.2564
JiangminTrojanDownloader.Homa.eip
WebrootW32.Malware.Gen
AviraTR/Crypt.XPACK.Gen
ArcabitTrojan.Barys.DA04
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win32.Homa.C103650
VBA32TScope.Malware-Cryptor.SB
ALYacGen:Variant.Barys.2564
MAXmalware (ai score=84)
MalwarebytesMalware.Heuristic.1006
TrendMicro-HouseCallTROJ_GEN.R03BC0RFP22
RisingTrojan.Win32.Generic.12A11D4B (C64:YzY0OkUj8Gx3kUTr)
YandexPacked/NTkrnl
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.3026537.susgen
FortinetW32/FakeAV.FE!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Barys.2564?

Barys.2564 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment