Malware

Barys.317267 (B) removal tips

Malware Removal

The Barys.317267 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.317267 (B) virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to stop active services
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior

How to determine Barys.317267 (B)?


File Info:

name: EEFA8CD00E2A0178BAE0.mlw
path: /opt/CAPEv2/storage/binaries/504353c74cb1be4085225779371ce4ff94171447a61818b0e8282284bdb31ba7
crc32: F3862086
md5: eefa8cd00e2a0178bae0c06350ac5872
sha1: b1d2023a83700402836cd7d7db102869ce4278ce
sha256: 504353c74cb1be4085225779371ce4ff94171447a61818b0e8282284bdb31ba7
sha512: 1bdffd3b743be5c62b8c7c24fcda536fc85bf809ed06fe902ff9ea44fe6ded76db4c336e68c71b772955b865864cd67050e20e7cd0d340d7dd14ab1b539cbb35
ssdeep: 6144:Z3ue8ySm8hQAAIfFrRXuEE+0l97mKwKvbqHVF2u86JQPDHDdx/Qtqa:D/zkFF+EExZmKbDuVFpPJQPDHvd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14B56CF2AB7C0C8F2C44580313799AE536DF9AC300265AA5BDBE4DE452FF91E4931A74F
sha3_384: 7a7271e22d04b9d1275ef566341b7ce34276025921483a7cbfb5ecf4fedd28149495d810540deb2f7734ae27b4796263
ep_bytes: 6a6068f0b74200e8edf7ffffbf940000
timestamp: 2006-12-09 05:13:03

Version Info:

0: [No Data]

Barys.317267 (B) also known as:

BkavW32.FxcaxMMUqhATTc.Worm
DrWebTrojan.Siggen.36621
MicroWorld-eScanGen:Variant.Barys.317267
FireEyeGeneric.mg.eefa8cd00e2a0178
CAT-QuickHealWorm.Pykspa.C3
ALYacGen:Variant.Barys.317267
MalwarebytesGeneric.Worm.Agent.DDS
ZillyaTrojan.Vilsel.Win32.2602
SangforARMADILLO17
K7AntiVirusTrojan ( 003da8d71 )
K7GWTrojan ( 003da8d71 )
Cybereasonmalicious.00e2a0
BitDefenderThetaGen:NN.ZexaF.34742.@pW@aybkH7d
VirITTrojan.Win32.Generic.SXQ
CyrenW32/Risk.BZSN-6837
SymantecW32.Pykspa.D
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.Agent.TG
APEXMalicious
ClamAVWin.Worm.Pykspa-1
KasperskyTrojan-Ransom.Win32.Blocker.jcen
BitDefenderGen:Variant.Barys.317267
NANO-AntivirusTrojan.Win32.Agent.ctkmgw
AvastWin32:Renos-KY [Trj]
TencentWorm.Win32.Pykspa.a
Ad-AwareGen:Variant.Barys.317267
TACHYONRansom/W32.Blocker.6316032.F
EmsisoftGen:Variant.Barys.317267 (B)
ComodoWorm.Win32.Autorun.Agent_TG0@1isiwy
F-SecureTrojan-Downloader:W32/Renos.gen!T
BaiduWin32.Worm.Autorun.o
VIPREGen:Variant.Barys.317267
TrendMicroWORM_AUTORUN_EK040404.UVPM
McAfee-GW-EditionBehavesLike.Win32.Dropper.vz
Trapminemalicious.high.ml.score
SophosML/PE-A + W32/Pykse-F
IkarusTrojan.Win32.AntiAV
GDataWin32.Trojan.BSE.1JWSKP9
JiangminTrojan/Blocker.lhz
AviraTR/Agent.327680.A
ArcabitTrojan.Barys.D4D753
ViRobotTrojan.Win32.Blocker.Gen.B
ZoneAlarmTrojan-Ransom.Win32.Blocker.jcen
MicrosoftTrojan:Win32/Dinwod.A!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zepfod.R4378
McAfeeW32/Pykse.worm.gen.a
MAXmalware (ai score=89)
VBA32Trojan.ChidikSun.28205
CylanceUnsafe
TrendMicro-HouseCallWORM_AUTORUN_EK040404.UVPM
RisingWorm.Autorun!1.BC87 (CLASSIC)
YandexTrojan.GenAsa!R41E4MI3PTc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Ransom.Blocker.iprw
FortinetW32/Agent.XEK!tr
AVGWin32:Renos-KY [Trj]
PandaTrj/Vilsel.B
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Barys.317267 (B)?

Barys.317267 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment