Malware

Barys.333308 removal guide

Malware Removal

The Barys.333308 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.333308 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • A HTTP/S link was seen in a script or command line
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Barys.333308?


File Info:

name: 96B2A220B9633C3A1225.mlw
path: /opt/CAPEv2/storage/binaries/9437d363aa1a06a68f66c30853a957348e09ac2946ef9f22ec0faa717c43dbf4
crc32: F6BC13B4
md5: 96b2a220b9633c3a122586af0cfe9dac
sha1: 5ec6742132f30794a884363f15243ce5dbb06881
sha256: 9437d363aa1a06a68f66c30853a957348e09ac2946ef9f22ec0faa717c43dbf4
sha512: f4f8b60b0b582d4ff53e9eba7583f25c3634e6d39f5d83c798fb5b048e83bf1418f97f3ed5bd257e663ce2b10346759eaf2bfbcdb1489a23ff891f995157cb25
ssdeep: 98304:V+kFirNcHu3bpXhiVvtgSndg/MS8lPQKwK1dW:Vr2NcHu3bBhkVgwdCMwKh1d
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T11F26BE52A2A000F9D877C178C5569623D7B2F8261371CBDB16A8D5790F33BE26E3E325
sha3_384: 902c1893488c6014d3085435d73be51b7c5b7c4135a110e25b73014ff65b241ff7a1241a20fd1a82b0b3c84be8d5cb7f
ep_bytes: 4883ec28e8ff0700004883c428e972fe
timestamp: 2022-11-20 06:53:14

Version Info:

0: [No Data]

Barys.333308 also known as:

MicroWorld-eScanGen:Variant.Barys.333308
FireEyeGen:Variant.Barys.333308
ALYacGen:Variant.Barys.333308
VIPREGen:Variant.Barys.333308
CyrenW64/Trojan.FHTU-2181
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win64/GenKryptik.FIZN
CynetMalicious (score: 100)
KasperskyRootkit.Win64.Agent.bhc
BitDefenderGen:Variant.Barys.333308
NANO-AntivirusTrojan.Win64.BtcMine.hwzqym
Ad-AwareGen:Variant.Barys.333308
EmsisoftGen:Variant.Barys.333308 (B)
F-SecureTrojan.RKIT/Agent.kabtt
DrWebTrojan.BtcMine.1580
GDataGen:Variant.Barys.333308
AviraRKIT/Agent.kabtt
MAXmalware (ai score=88)
Antiy-AVLTrojan[Rootkit]/Win64.Agent
ArcabitTrojan.Barys.D515FC
ZoneAlarmRootkit.Win64.Agent.bhc
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
MalwarebytesHackTool.GameHack
RisingRootkit.Agent!8.F5 (CLOUD)
YandexTrojan.GenAsa!4FDGig1OUts
IkarusTrojan.Win64.Crypt
MaxSecureTrojan.Malware.300983.susgen
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Barys.333308?

Barys.333308 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment