Malware

Barys.265794 removal tips

Malware Removal

The Barys.265794 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.265794 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Barys.265794?


File Info:

name: A9A35C1AA9E7887F0BC1.mlw
path: /opt/CAPEv2/storage/binaries/b27358b320c8e2f31ff9dfd913ada31d014e4ad8117b19713b07cf8c8a6b1de3
crc32: D3A0E316
md5: a9a35c1aa9e7887f0bc1b8661be9388c
sha1: fab11767900f255f8acda09252b6052028916c30
sha256: b27358b320c8e2f31ff9dfd913ada31d014e4ad8117b19713b07cf8c8a6b1de3
sha512: b972a35e232751dbd475bb43d0791227c553dda9189b6ecc0cb784a53c0fde457c5487eb1a15e877042cef1830113d7754a364b4327d8e2309931af623477208
ssdeep: 24576:zfUc+v6ZpwbgQxW/BFXu2NmT48RS6KPXsscGQO9zreHe6hse9TDCM:zfDtZhiW/y2Nqha8XHO1N6hsSnCM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1654523AD8BD40D00D2A0D03C2C0A9B1A5BAC99366F4744FA349F5552FAD10BFF3795AD
sha3_384: 93f188e049910ca7d3252707e82667bde53c3252d6b6ba978bfa157cde4474b3e212a1294313f317099fdc49e0d8032a
ep_bytes: 680bc34b00e910000000f2d2e9090000
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Barys.265794 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.265794
FireEyeGeneric.mg.a9a35c1aa9e7887f
McAfeeBackDoor-EXZ
CylanceUnsafe
K7AntiVirusTrojan ( 0052c8a31 )
K7GWTrojan ( 0052c8a31 )
Cybereasonmalicious.aa9e78
BitDefenderThetaAI:Packer.599AA70016
VirITTrojan.Win32.Agent.BWB
ESET-NOD32a variant of Win32/Autoit.EJ
ClamAVWin.Trojan.Zegost-7495611-0
KasperskyHEUR:Backdoor.Script.LodaRat.b
BitDefenderGen:Variant.Barys.265794
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastAutoIt:Dropper-DU [Trj]
Ad-AwareGen:Variant.Barys.265794
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Barys.265794 (B)
IkarusTrojan.Autoit
AviraHEUR/AGEN.1200134
MAXmalware (ai score=83)
MicrosoftPWS:Win32/Zbot!ml
ZoneAlarmHEUR:Backdoor.Script.LodaRat.b
GDataGen:Variant.Barys.265794
CynetMalicious (score: 100)
Acronissuspicious
ALYacGen:Variant.Barys.265794
VBA32BScope.Trojan.AutoIt.Agent
MalwarebytesMalware.AI.416654916
APEXMalicious
RisingTrojan.Agent/Autoit!1.BC29 (CLASSIC)
FortinetW32/Filecoder.FV!tr.ransom
AVGAutoIt:Dropper-DU [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Barys.265794?

Barys.265794 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment