Malware

About “Barys.268 (B)” infection

Malware Removal

The Barys.268 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.268 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Barys.268 (B)?


File Info:

name: 585FFBD4A04BDC6747E8.mlw
path: /opt/CAPEv2/storage/binaries/a12e9b0b41d2f0ce22e5cc049fad09c8c1e5ead8f18b658789f763f9cfc4be87
crc32: 1B6EE883
md5: 585ffbd4a04bdc6747e8940c868759d6
sha1: 6d348eb83a83d200a20fd654f4801da78dd1e972
sha256: a12e9b0b41d2f0ce22e5cc049fad09c8c1e5ead8f18b658789f763f9cfc4be87
sha512: 2ce7cf3b1a5ef555337ff4477579451ef779305374f3ac132e1427ea58987872159aa811fdab7dd681d46bd5887b9e8a69d79d14e3fd818e01b015b5fc91a773
ssdeep: 6144:idi5aKl/9f8AbGcdeoDW+/OWtb9yOPmeAVbfP1r4riA7AroW+nYaFyzf/H551Fjn:iGx/9UtO2TW00UM5AEPoViJAndeyCg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E564D176ADA02939F92784B1691983862C0E1E7B1746FC6BA3D0776474B05E3B6F031F
sha3_384: f68b9f7361d3f6b9454177b1f72ef9f22a5dcabff1eeb08efaec16d17c6cb9521c11f7df33faf38311aca72057738344
ep_bytes: 6898404000e8eeffffff000050000000
timestamp: 1997-03-21 11:25:45

Version Info:

ProductName:
FileVersion:
:

Barys.268 (B) also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.lvqp
tehtrisGeneric.Malware
DrWebTrojan.VbCrypt.81
MicroWorld-eScanGen:Variant.Barys.268
ClamAVWin.Trojan.Vobfus-6
FireEyeGeneric.mg.585ffbd4a04bdc67
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Variant.Barys.268
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.9dc901a3
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZevbaF.36250.tm0@aiWcFyci
VirITTrojan.Win32.Zyx.JK
CyrenW32/Vobfus.AD.gen!Eldorado
SymantecW32.SillyFDC
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AUB
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.dexi
BitDefenderGen:Variant.Barys.268
NANO-AntivirusTrojan.Win32.VB.rilqt
SUPERAntiSpywareTrojan.Agent/Gen-Ursnif
AvastWin32:VB-ACAZ [Trj]
TencentWorm.Win32.Vobfus.n
TACHYONTrojan/W32.VB-Agent.311296.BT
EmsisoftGen:Variant.Barys.268 (B)
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Trojan.VBObfus.f
VIPREGen:Variant.Barys.268
TrendMicroWORM_VOBFUS.SMJA
McAfee-GW-EditionBehavesLike.Win32.VBObfus.fm
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-W
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.268
JiangminTrojan/Vbobf.b
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.VB.AUA@4o7zkg
ArcabitTrojan.Barys.268
ViRobotTrojan.Win32.A.VB.311296.D
ZoneAlarmWorm.Win32.Vobfus.dexi
MicrosoftTrojan:Win32/Otran!gmb
GoogleDetected
AhnLab-V3Trojan/Win.VB.R558885
McAfeeVBObfus.dv
MAXmalware (ai score=80)
VBA32BScope.Trojan.VB.Onechki
MalwarebytesGeneric.Worm.AutoRun.DDS
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMJA
RisingTrojan.VBEx!1.99EE (CLASSIC)
YandexTrojan.GenAsa!lh3wojJu4pE
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ACAZ [Trj]
Cybereasonmalicious.4a04bd
DeepInstinctMALICIOUS

How to remove Barys.268 (B)?

Barys.268 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment