Malware

Should I remove “Barys.3506”?

Malware Removal

The Barys.3506 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.3506 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

trybesmart.in

How to determine Barys.3506?


File Info:

crc32: DDB0770F
md5: fc201d43a08c15bbcd4fbfe9f05d512f
name: FC201D43A08C15BBCD4FBFE9F05D512F.mlw
sha1: 6d0fc7ae7cfaa264675712e738fe13e5bafcfab0
sha256: aeff582204861c8db3428a9eea0ae01cb96b3776765b42ab94e9581bfb90a329
sha512: be8f8ce12c68c744796e2a954d080ed8cf986a848fc5f49b437d52ebfa1ce5ba508eaa3cfb8fd5f364114431d1858af09c248b234bc587cf2956b326118a525c
ssdeep: 768:PteQTGQZJo++9kmumo10BTDLMMrSyvlrQueUb8fSbZaVA/yEvR:1X5JF+t7Nvt8yZaW/ZR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 1, 0, 0, 1
ProductVersion: 1, 0, 0, 1
FileVersion: 1, 0, 0, 1
OriginalFilename: Nnfow.exe
CompanyName: Kbtgkv
Translation: 0x0409 0x04e4

Barys.3506 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0040f0751 )
Elasticmalicious (high confidence)
ALYacGen:Variant.Barys.3506
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Barys.3506
K7GWTrojan ( 0040f0751 )
Cybereasonmalicious.3a08c1
BitDefenderThetaGen:NN.ZexaF.34758.eu0@amv!E7li
SymantecTrojan.Smoaler!gen3
ESET-NOD32Win32/Weelsof.A
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.PornoAsset.gfb
NANO-AntivirusTrojan.Win32.Winlock.rigzd
SUPERAntiSpywareTrojan.Agent/Gen-FakeAlert[ZBot]
MicroWorld-eScanGen:Variant.Barys.3506
TencentWin32.Trojan.Pornoasset.drmm
Ad-AwareGen:Variant.Barys.3506
SophosML/PE-A + Troj/Ransom-GC
ComodoSuspicious@#1mtas5vxmvdvi
DrWebTrojan.Winlock.5994
FireEyeGeneric.mg.fc201d43a08c15bb
EmsisoftGen:Variant.Barys.3506 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PornoAsset.bif
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.169520D
KingsoftWin32.Troj.Weelsof.A.(kcloud)
ArcabitTrojan.Barys.DDB2
AegisLabTrojan.Win32.PornoAsset.j!c
GDataGen:Variant.Barys.3506
Acronissuspicious
VBA32Hoax.PornoAsset
MAXmalware (ai score=80)
RisingTrojan.Generic@ML.98 (RDML:jKzOxOFIY/hZ+2b/lUxQ6A)
IkarusTrojan-Spy.Win32.SpyEyes
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Dofoil.Y!tr
PandaGeneric Malware

How to remove Barys.3506?

Barys.3506 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment