Malware

Barys.385408 (B) removal guide

Malware Removal

The Barys.385408 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.385408 (B) virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Barys.385408 (B)?


File Info:

name: 3C6A4273FC651714ADAA.mlw
path: /opt/CAPEv2/storage/binaries/507bb63d0c34c256adde35a3b0212890b19eb7b7c85166a11c81c6d15ac7f893
crc32: 28E81717
md5: 3c6a4273fc651714adaa5aff85544af1
sha1: bc6838ae4ac9231579df6d5f5cf1f32e019c42d9
sha256: 507bb63d0c34c256adde35a3b0212890b19eb7b7c85166a11c81c6d15ac7f893
sha512: 6439ed1f3df8713c5d8d984cf69777c98089ed5624ebd3d0cde703782f0cf518135a8ac8c0b536bf45dfd5a7252ede5ab79d9e53624423686c4d5c6de5930bd0
ssdeep: 6144:EhjxrU2+7kO+4LT9FD/QOuVkJpFYcEOkCybEaQRXr9HNdvOaAC6:Evr+M4H9FrGVkwOkx2LIat6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T136C47D25BAA08073C167957984E257ABFBB2B53123205ACF6390075A5F237E3BD3631D
sha3_384: e3e168bfdc3c9496a071a3bf1a91b4cbee5c0e1b4bcdce70d8e9ea76f994d8ffa8ac820ee72d2a1a3b02c6deeed601ad
ep_bytes: e82a370000e979feffff8bff558bec5d
timestamp: 2023-02-01 08:55:40

Version Info:

FileVersion: 23, 2, 1, 1655
ProductVersion: 23, 2, 1, 1655
Translation: 0x0804 0x04b0

Barys.385408 (B) also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.385408
ClamAVWin.Malware.Barys-10002593-0
ALYacGen:Variant.Barys.385408
MalwarebytesMalware.AI.2915880422
VIPREGen:Variant.Barys.385408
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0054a11a1 )
AlibabaBackdoor:Win32/Gulpix.02c5fa6f
K7GWTrojan ( 0054a11a1 )
Cybereasonmalicious.3fc651
CyrenW32/Injector.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Sfuzuan.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.Win32.Gulpix.gen
BitDefenderGen:Variant.Barys.385408
NANO-AntivirusTrojan.Win32.Gulpix.jvcdmi
AvastWin32:BackdoorX-gen [Trj]
TencentMalware.Win32.Gencirc.10be9d9b
EmsisoftGen:Variant.Barys.385408 (B)
F-SecureHeuristic.HEUR/AGEN.1321580
DrWebTrojan.Siggen19.38825
ZillyaTrojan.Sfuzuan.Win32.792
TrendMicroTROJ_GEN.R002C0PDM23
McAfee-GW-EditionBehavesLike.Win32.Corrupt.hm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.3c6a4273fc651714
SophosMal/Behav-010
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.13ZLGFG
JiangminTrojan.Generic.hpxjb
AviraHEUR/AGEN.1321580
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Caynamer
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Barys.D5E180
ZoneAlarmHEUR:Backdoor.Win32.Gulpix.gen
MicrosoftTrojan:Win32/Tiggre!rfn
GoogleDetected
AhnLab-V3Malware/Win.Generic.R568445
McAfeeArtemis!3C6A4273FC65
TACHYONBackdoor/W32.Gulpix.558080
VBA32Trojan.Tiggre
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0PDM23
RisingTrojan.Generic!8.C3 (TFE:5:DS9Yj43AhrI)
IkarusTrojan.Win32.Sfuzuan
MaxSecureTrojan.Malware.74000219.susgen
FortinetW32/Sfuzuan.AB!tr
BitDefenderThetaGen:NN.ZexaF.36196.Iu0@aC5etvmj
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Barys.385408 (B)?

Barys.385408 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment