Malware

Barys.2608 removal guide

Malware Removal

The Barys.2608 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.2608 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Barys.2608?


File Info:

crc32: 679B5154
md5: 12a2fd95a16b487d332acd96deb21807
name: 12A2FD95A16B487D332ACD96DEB21807.mlw
sha1: 54b9946f707eae01d691f41eed3aa433236705a8
sha256: f5c316fc53eea442225bede3a5483a6519efc6563060715014dd91770b79bdd9
sha512: 8f65fd674455a28725de9d992b047ce8bcf335d4b215f8bc6f6f0ed0785e399f4c8ae210d1cbefe40a509ed96dd0196b72ce961a37d9ff6f9ce69b833f2a8c37
ssdeep: 6144:kOVrSyPT1mSv0agImaMdxbk0y4u/ss66hblCxa:k6rS0T0X79dhk0csN6hblp
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9 Edwin Lash 1998-2010
InternalName: Craps
FileVersion: 9.6
CompanyName: Spawn Ampere
ProductName: Symbol Tonic
ProductVersion: 9.6
FileDescription: Handy Chile
OriginalFilename: Drill.exe
Translation: 0x0409 0x04b0

Barys.2608 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.3333
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Generic
ALYacGen:Variant.Barys.2608
CylanceUnsafe
ZillyaTrojan.ChameleonUnlicence.Win32.6
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/Obfuscator.586121b6
Cybereasonmalicious.5a16b4
CyrenW32/Zbot.DA.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.QTE
APEXMalicious
AvastFileRepMetagen [Malware]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.2608
NANO-AntivirusTrojan.Win32.Fullscreen.edtsr
ViRobotTrojan.Win32.S.Fullscreen.245248
MicroWorld-eScanGen:Variant.Barys.2608
TencentWin32.Trojan.Generic.Dxmw
Ad-AwareGen:Variant.Barys.2608
SophosML/PE-A + Mal/EncPk-AAI
ComodoTrojWare.Win32.Trojan.XPACK.Gen@2ho5ur
BitDefenderThetaAI:Packer.520771981F
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Weenloc.R002C0DET21
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dc
FireEyeGeneric.mg.12a2fd95a16b487d
EmsisoftGen:Variant.Barys.2608 (B)
JiangminTrojan/Fullscreen.bg
WebrootW32.Trojan.Gen
AviraTR/Crypt.ULPM.Gen
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.F6428A
MicrosoftRansom:Win32/Weenloc.A
GDataGen:Variant.Barys.2608
TACHYONTrojan/W32.Birele.245248
McAfeeArtemis!12A2FD95A16B
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
PandaGeneric Malware
TrendMicro-HouseCallRansom_Weenloc.R002C0DET21
YandexTrojan.Fullscreen!hXT3aThV+8w
IkarusTrojan-Ransom.Fullscreen
MaxSecureTrojan.Malware.2747790.susgen
FortinetW32/LockScreen.AGU!tr
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml

How to remove Barys.2608?

Barys.2608 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment