Malware

Barys.268 malicious file

Malware Removal

The Barys.268 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.268 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Barys.268?


File Info:

name: EC4F0B3F9091A1AC2CDE.mlw
path: /opt/CAPEv2/storage/binaries/97151ee44ca8f8de283265422a7d1bf7e55a35fc39445ff8898327edea1d2900
crc32: 35A14EB3
md5: ec4f0b3f9091a1ac2cde80a6ca471304
sha1: 976e485b1cc705fc318ea4fdb431bc9f04b8bc42
sha256: 97151ee44ca8f8de283265422a7d1bf7e55a35fc39445ff8898327edea1d2900
sha512: 4f5769f3181ac216076317327ef86f886a030bcbe69c45a0344c28a6417ae524714b2b853ecc4c1d196dd90da9f2e99946bc7a29e85b1d9dbab00250bd4b03e2
ssdeep: 6144:KdXaKl/9f8AbGcdeoDW+/OWtb9yOPmeAVbfP1r4riA7AroW+nYaFyzf/H551Fjme:Klx/9UtO2TW00UM5AEPoViJAndeyCg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A964D176ADA02939F92784B1691983862C0E1E7B1746FC6BA3D0776474B05E3B6F031F
sha3_384: 3c7a308a85c363461745630a5329ad54cb7ba2346ebb9da727c282ee680187cdad84e5dc3fe46bf282f61a2b0332dfab
ep_bytes: 6898404000e8eeffffff000050000000
timestamp: 1997-03-21 11:25:45

Version Info:

ProductName:
FileVersion:
:

Barys.268 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.lvqp
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Barys.268
ClamAVWin.Trojan.Vobfus-6
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Variant.Barys.268
MalwarebytesGeneric.Worm.AutoRun.DDS
ZillyaWorm.Vobfus.Win32.1175626
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.577a058e
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.f9091a
BitDefenderThetaGen:NN.ZevbaF.36196.tm0@aiWcFyci
VirITTrojan.Win32.Zyx.JK
CyrenW32/Vobfus.AD.gen!Eldorado
SymantecW32.SillyFDC
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AUB
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.dexi
BitDefenderGen:Variant.Barys.268
NANO-AntivirusTrojan.Win32.VB.rilqt
SUPERAntiSpywareTrojan.Agent/Gen-Ursnif
AvastWin32:VB-ACAZ [Trj]
TencentWorm.Win32.Vobfus.n
TACHYONTrojan/W32.VB-Agent.311296.BT
EmsisoftGen:Variant.Barys.268 (B)
BaiduWin32.Trojan.VBObfus.f
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.VbCrypt.81
VIPREGen:Variant.Barys.268
TrendMicroWORM_VOBFUS.SM13
McAfee-GW-EditionBehavesLike.Win32.VBObfus.fm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.ec4f0b3f9091a1ac
SophosMal/SillyFDC-W
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Vbobf.b
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftTrojan:Win32/Otran!gmb
XcitiumWorm.Win32.VB.AUA@4o7zkg
ArcabitTrojan.Barys.268
ViRobotTrojan.Win32.A.VB.311296.D
ZoneAlarmWorm.Win32.Vobfus.dexi
GDataWin32.Trojan.VB.AAO
GoogleDetected
AhnLab-V3Trojan/Win.VB.R545763
McAfeeVBObfus.dv
MAXmalware (ai score=87)
VBA32BScope.Trojan.VB.Onechki
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SM13
RisingTrojan.VBEx!1.99EE (CLASSIC)
YandexTrojan.GenAsa!lh3wojJu4pE
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ACAZ [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Barys.268?

Barys.268 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment