Malware

What is “Barys.380893”?

Malware Removal

The Barys.380893 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.380893 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial language used in binary resources: Spanish (Modern)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Bochs through the presence of a registry key
  • Attempted to write directly to a physical drive
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Barys.380893?


File Info:

name: 1E9F7130F09A6E7C2C7B.mlw
path: /opt/CAPEv2/storage/binaries/ce2f05295edfb961d49edaa2d271b6c456f4d5150997f777c3dacb71dca5bb08
crc32: 178DF39E
md5: 1e9f7130f09a6e7c2c7b5b9a373f4310
sha1: d89efcd3c3cac59a2b081270dee1b7d7ab1c8baa
sha256: ce2f05295edfb961d49edaa2d271b6c456f4d5150997f777c3dacb71dca5bb08
sha512: 7abe4ebe5b098203308956da15bb917d8ba8ab0ed9b8c1cf7aebc8f31e38f4d4285226d3618ee229409d9d77b1708cfd73950caf792decd7331b2cee6f643381
ssdeep: 12288:UW7wSu2cBcfXYLV5PPnY1cTM8VJsrpHdI2G8uJ+d9nkYMjAXQ3e2F1ynninVM:UVS2CfoT3Y1korp9JTr90AXQ3hGinVM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F805121BA2E1F232E40286F42B96C1E082AA7D3369C39C1BF7C45F4976F19DB44517A7
sha3_384: 38d033981dd21fdae6a03b402393f8325c6337e5af80fb78b55b87fff4963a82efd7eca678db295c64e36fa86307a99b
ep_bytes: 68603d4000e8eeffffff000000000000
timestamp: 2009-07-26 18:55:34

Version Info:

Translation: 0x0c0a 0x04b0
CompanyName: HeadAche Lab's
ProductName: SigNYSTB
FileVersion: 1.00
ProductVersion: 1.00
InternalName: SigNYSTB
OriginalFilename: SigNYSTB.exe

Barys.380893 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Barys.380893
ALYacGen:Variant.Barys.380893
ZillyaWorm.Kolab.Win32.3473
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 004c04dc1 )
AlibabaWorm:Win32/Kolab.bc44a71d
K7GWTrojan ( 004c04dc1 )
Cybereasonmalicious.0f09a6
VirITTrojan.Win32.Generic.ALPJ
CyrenW32/Risk.MVEQ-5889
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.CWB
APEXMalicious
ClamAVWin.Worm.Kolab-596
KasperskyNet-Worm.Win32.Kolab.kfv
BitDefenderGen:Variant.Barys.380893
NANO-AntivirusTrojan.Win32.Kolab.incsm
AvastWin32:VB-PVA [Drp]
TencentMalware.Win32.Gencirc.114f6e20
EmsisoftGen:Variant.Barys.380893 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.MulDrop3.7239
VIPREGen:Variant.Barys.380893
McAfee-GW-EditionBehavesLike.Win32.Lockbit.bc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.1e9f7130f09a6e7c
SophosMal/Generic-G
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Barys.380893
JiangminWorm/Kolab.mna
WebrootVir.Tool.Gen
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=99)
Antiy-AVLWorm[Net]/Win32.Kolab
XcitiumMalware@#3ig52o2vgozqb
ArcabitTrojan.Barys.D5CFDD
ZoneAlarmNet-Worm.Win32.Kolab.kfv
MicrosoftVirTool:Win32/VBInject.UG
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Kolab.C5948
McAfeeGenericRXAA-AA!1E9F7130F09A
VBA32Trojan.VBRA.013295
Cylanceunsafe
PandaTrj/CI.A
RisingHackTool.VBInject!8.1A0 (TFE:3:86Bt1thJnmL)
YandexTrojan.GenAsa!N5TWUp1AxsY
IkarusVirus.Win32.VBInject
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBInjector.W!tr
BitDefenderThetaGen:NN.ZevbaF.36250.Wq0@aaWJ0cP
AVGWin32:VB-PVA [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Barys.380893?

Barys.380893 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment