Malware

What is “Barys.26945”?

Malware Removal

The Barys.26945 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.26945 virus can do?

  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid

How to determine Barys.26945?


File Info:

name: E54E0565B270FB2AA6F6.mlw
path: /opt/CAPEv2/storage/binaries/1bb5237331c15ea0a9f82eaa7b5a282c284e96740655768ad87a92a8b39d3724
crc32: 0F4904A6
md5: e54e0565b270fb2aa6f66ec51bb2ed1c
sha1: aa06906376b8eaa2f60b7ac7e715a8468646a8c6
sha256: 1bb5237331c15ea0a9f82eaa7b5a282c284e96740655768ad87a92a8b39d3724
sha512: c69938f9ef1df548303c9b08ae998c2861d1c4ab186b7dedc544b5a122bcce09229584960b4eb07180f0e1a79a6f11678b7084c51f7e0b0e96c58b89a47a026d
ssdeep: 1536:sJn/RY7jt+0VbADrKj3Ae+TlkG4CvopoSIfmI2HwOxKIibs12XxM8MwMUb6MuMbH:sReX6Szy9EowqRzKP/KR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DA94ED263BA6D54BC6E48E387EABC213A6ADDF9283F700052AD53071DEB514C38935B5
sha3_384: 915afb2931635e2ba35057b96dd37e092cce73edca1faa68bb92228a73108c0a49dc6717a4a519bc0a38070a334ac060
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-11-07 13:51:26

Version Info:

0: [No Data]

Barys.26945 also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
FireEyeGeneric.mg.e54e0565b270fb2a
VIPREGen:Variant.Barys.26945
CrowdStrikewin/malicious_confidence_100% (W)
SymantecMSIL.Downloader!gen8
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Trojan-Ransom.MSIL.Blocker.gen
BitDefenderGen:Variant.Barys.26945
MicroWorld-eScanGen:Variant.Barys.26945
Ad-AwareGen:Variant.Barys.26945
EmsisoftGen:Variant.Barys.26945 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.26945
ArcabitTrojan.Barys.D6941
MicrosoftTrojan:Win32/Woreflint.A!cl
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.34754.zm0@aWXnZ2h
ALYacGen:Variant.Barys.26945
MAXmalware (ai score=83)
VBA32Downloader.MSIL.gen.rexp
RisingTrojan.Generic/MSIL@AI.97 (RDM.MSIL:xz9EV7V/w6jM51d8By0SlA)
IkarusWin32.Outbreak
MaxSecureTrojan.Malware.300983.susgen
AVGRATX-gen [Trj]
AvastRATX-gen [Trj]

How to remove Barys.26945?

Barys.26945 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment