Malware

Barys.361879 information

Malware Removal

The Barys.361879 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.361879 virus can do?

  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Barys.361879?


File Info:

name: 7A9D5174FE4D5003199E.mlw
path: /opt/CAPEv2/storage/binaries/e3d825f2356175cdcba75c3139a27a6d1b77790353d8f17a820176a530098db2
crc32: 7AA0A38C
md5: 7a9d5174fe4d5003199ee5d75fa17759
sha1: 138f4a583371a20902c6d284d7b6547d366fa42a
sha256: e3d825f2356175cdcba75c3139a27a6d1b77790353d8f17a820176a530098db2
sha512: 5d35ddd6c4a30b8301218e4f07ed57b784eefebea6df35034969f5371b2a9ac56ada22acf073259163fe9481ff02887c7b644ff674456b589b76c847e1250318
ssdeep: 96:HMoG79JqpjO/WIVB8OVM0Y08b2Bkwc0m:gJ4u7hG0K2SN
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1E9E110256BD0243BD0F68B35C9F30387F960F8053A365A4E58C703586D9376B6E812AD
sha3_384: d496c9c462ece0a1cc9bd6c4fd5b9fe2290770102ff1c6b3ae7b9245d7d0d9be56ef01b31aba130067b3d5ce524cf274
ep_bytes: ff250020400000000000000000000000
timestamp: 1970-01-01 00:00:00

Version Info:

Translation: 0x007f 0x04b0
Comments:
CompanyName:
FileDescription:
FileVersion: 0.0.0.0
InternalName: xyh
LegalCopyright:
LegalTrademarks:
OriginalFilename: xyh.exe
ProductName:
ProductVersion:

Barys.361879 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.361879
ClamAVWin.Malware.Razy-6915301-0
ALYacGen:Variant.Barys.361879
MalwarebytesTrojan.Injector
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 700000121 )
K7AntiVirusTrojan ( 700000121 )
BitDefenderThetaGen:NN.ZemsilF.36250.am1@aGA7mfi
CyrenW32/MSIL_Troj.YU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Tiny.F
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.361879
AvastWin32:TrojanX-gen [Trj]
EmsisoftGen:Variant.Barys.361879 (B)
F-SecureHeuristic.HEUR/AGEN.1308486
DrWebBackDoor.Siggen2.2068
VIPREGen:Variant.Barys.361879
TrendMicroTROJ_SMOLCIL.SMA
McAfee-GW-EditionGenericRXEA-QF!7A9D5174FE4D
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.7a9d5174fe4d5003
SophosTroj/Tiny-DI
IkarusTrojan.MSIL.Tiny
GDataGen:Variant.Barys.361879
AviraHEUR/AGEN.1308486
ArcabitTrojan.Barys.D58597
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:MSIL/Tiny.AC!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.RL_Generic.C3464443
Acronissuspicious
McAfeeGenericRXEA-QF!7A9D5174FE4D
MAXmalware (ai score=84)
Cylanceunsafe
TrendMicro-HouseCallTROJ_SMOLCIL.SMA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Tiny.F!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Barys.361879?

Barys.361879 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment