Malware

How to remove “Barys.27545”?

Malware Removal

The Barys.27545 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.27545 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Deletes executed files from disk

How to determine Barys.27545?


File Info:

name: 8D77FE55CF00E1A9EC91.mlw
path: /opt/CAPEv2/storage/binaries/e0dfb126720517f5de908d3483a6304ab2e184cbc44922eb22d39df147b204fe
crc32: 58E6F4F0
md5: 8d77fe55cf00e1a9ec9154b24fdca8b7
sha1: 34f58b3d267847a9f9ce7fe689336e919dac9ed3
sha256: e0dfb126720517f5de908d3483a6304ab2e184cbc44922eb22d39df147b204fe
sha512: 1166923a1afc6efdde74d02ca6b7d144b3be0e5e27f9d175961057bf7f7d9c9eed692bd80e35d61b6c6e77df919fadcbedd43d0c86f23c3b2b8e42e2940c7601
ssdeep: 24576:/4nXu/QSDTV+Bnvu8t8WqGV7qHdmGDVDOm+iS+9zVsIMysm1NhEqPJCsuqN867+l:/qeNVM7wppDj+iS+9xse2su+7+xI2P
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D595DF3FB268653ED5AF4B3245B39260997BBB61A91B8C1E07F0081DCF664701E3FA15
sha3_384: e085e8898ed0e57500bdda1957e06838c0a146d671b5790d5dc1773cd1dd6a61e378e5519d979173ee2a36c391dde81a
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2020-05-21 05:56:23

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Michael Agarkov
FileDescription: Time Counter Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Time Counter
ProductVersion: 1.0
Translation: 0x0000 0x04b0

Barys.27545 also known as:

MicroWorld-eScanGen:Variant.Barys.27545
VIPREGen:Variant.Barys.27545
Cybereasonmalicious.5cf00e
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.27545
EmsisoftGen:Variant.Barys.27545 (B)
FireEyeGen:Variant.Barys.27545
GDataGen:Variant.Barys.27545
ArcabitTrojan.Barys.D6B99
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Script/Wacatac.B!ml
ALYacGen:Variant.Barys.27545
MAXmalware (ai score=83)
BitDefenderThetaGen:NN.ZemsilF.34806.DmY@a82q@Ld

How to remove Barys.27545?

Barys.27545 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment