Malware

What is “Barys.383551”?

Malware Removal

The Barys.383551 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.383551 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Barys.383551?


File Info:

name: DBA75C1768C595345A30.mlw
path: /opt/CAPEv2/storage/binaries/b971f7d2db082b2ae88fcf772a2e85287057b27ded0166529b6385184e24359a
crc32: 83C30C08
md5: dba75c1768c595345a30106f6288de07
sha1: 0eefb5869239b9fdc6fa21adcd7978f9f7e2c3af
sha256: b971f7d2db082b2ae88fcf772a2e85287057b27ded0166529b6385184e24359a
sha512: 01795d2610fe4afcf745d17ec2929d738e3ec0176b28d9570cb1452a52d23bc2e7c553b8bfa2642faac73a8b64c05026eb0686bac3b2720d7d085b343fc9bd27
ssdeep: 49152:C1aQyugcKeQS49NH3bn+t4zcZO2nYNMK8rJ2y/gwL9XcZ:CUQyOVQSOh+azcdnYKzd2URq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T154A53397C4B088A9F930DC3165EBFCDAC647564B2670E212ED0BC7C480B7BC9A59661F
sha3_384: 1c81ce1240993e53f1856e3c7d5c49902a0e865cf1c8e14bb4b8f4c87c700942d7c5735885da497858d7ea2c79bd2dac
ep_bytes: 60be00308e008dbe00e0b1ff5783cdff
timestamp: 2021-07-09 05:00:24

Version Info:

CompanyName: Microsoft Corporation
FileDescription: 基础应用类程序
FileVersion: 1.0.0.0
InternalName: R2登录器
LegalCopyright: 2021 (C) Microsoft Copyright All.
OriginalFilename: _R2登录器.exe
ProductName: R2 登录器
ProductVersion: 1.0.0.0
PrivateBuild: 基础应用类程序
SpecialBuild: 基础应用类程序
Comments: 基础应用类程序
Translation: 0x0804 0x04b0

Barys.383551 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Barys.383551
FireEyeGeneric.mg.dba75c1768c59534
McAfeeArtemis!DBA75C1768C5
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005376ae1 )
K7GWTrojan ( 005376ae1 )
Cybereasonmalicious.69239b
BitDefenderThetaGen:NN.ZexaF.36350.aoKfa4yOy7bb
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R011C0PHP23
KasperskyTrojan.Win32.Injuke.hqvd
BitDefenderGen:Variant.Barys.383551
AvastWin32:Malware-gen
SophosMal/FakeAV-EWN
F-SecureTrojan.TR/ATRAPS.Gen
VIPREGen:Variant.Barys.383551
TrendMicroTROJ_GEN.R011C0PHP23
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Barys.383551 (B)
IkarusTrojan.Win32
GoogleDetected
AviraTR/ATRAPS.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.FlyStudio.a
MicrosoftProgram:Win32/Wacapew.C!ml
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Barys.D5DA3F
ZoneAlarmTrojan.Win32.Injuke.hqvd
GDataWin32.Trojan.PSE.1KQMTX4
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Trojan.Tiggre
ALYacGen:Variant.Barys.383551
Cylanceunsafe
RisingVirus.Sality!8.35A (TFE:5:U1dQ8kSH43)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CoinMiner.PHP!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Barys.383551?

Barys.383551 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment