Malware

How to remove “Barys.4004”?

Malware Removal

The Barys.4004 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.4004 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Barys.4004?


File Info:

name: BC3214DA5AAC705C58A2.mlw
path: /opt/CAPEv2/storage/binaries/96260b914a968484763331fa6cd6c67034f9a6d1fedc541b2bf1946c549ec6c5
crc32: F6827D5E
md5: bc3214da5aac705c58a2173c652e031e
sha1: 85c96cb2e1c5803d9dddf8ee2060f6132c5f3ffd
sha256: 96260b914a968484763331fa6cd6c67034f9a6d1fedc541b2bf1946c549ec6c5
sha512: 9147fae233f0caa67f8d92fb1cffcfbd54bda68b62e31b00e5d4630f6c6f3f33a10b0b3f5a0adce0b00e6ee1c7610a304c936c9eae31252c3f9068008fe5d30d
ssdeep: 3072:JwtJN7AfQnPBbj0Dt2JLVvXtJq2338RF46YMyQV4MsWl/5WG7l5Ghkhl:W7+QPBbG2TdJz38RF41Wl/F7R
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18614E1522DABD9A8E633ED7CC76F62B56138ED6CCC808E7172C64C58FC292A45B51423
sha3_384: f7ed3b453301c52b1d1c900d844babb39f1f88ea28833e3f89f97f3583e9eb36ed37dce3e0f5aebae8a20bfe36c37a1f
ep_bytes: 833debd04200ff8b05ecd0420085c00f
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Barys.4004 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Jorik.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.4004
ALYacGen:Variant.Barys.4004
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.776224
SangforWorm.Win32.Stekct.A
K7AntiVirusTrojan ( 0055dd191 )
AlibabaWorm:Win32/Slenping.dd60bb4f
K7GWTrojan ( 0055dd191 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Virus.Krap.a
CyrenW32/Backdoor.IXXZ-1416
SymantecPacked.Generic.382
ESET-NOD32a variant of Win32/Kryptik.AFJE
APEXMalicious
AvastWin32:Susn-AU [Trj]
ClamAVWin.Trojan.Bublik-382
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.4004
NANO-AntivirusTrojan.Win32.SmsSend.cbobaq
TencentWin32.Trojan.Generic.Pgco
Ad-AwareGen:Variant.Barys.4004
SophosMal/Generic-R + Mal/EncPk-AEH
ComodoApplicUnwnt.Win32.Hoax.ArchSMS.SIE@4p73hg
DrWebTrojan.SMSSend.2363
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroBKDR_POISONIVY.D
McAfee-GW-EditionBehavesLike.Win32.ZBot.ch
FireEyeGeneric.mg.bc3214da5aac705c
EmsisoftGen:Variant.Barys.4004 (B)
IkarusTrojan.Win32.Bublik
JiangminTrojan/Bublik.bm
WebrootW32.Malware.Heur
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1293F6C
KingsoftWin32.Troj.Generic.a.(kcloud)
MicrosoftWorm:Win32/Stekct.A
ArcabitTrojan.Barys.DFA4
SUPERAntiSpywareTrojan.Agent/Gen-Exploiter
GDataGen:Variant.Barys.4004
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R25035
Acronissuspicious
McAfeePWS-Zbot.gen.bfi
MAXmalware (ai score=100)
VBA32Trojan.PoisonIvy
MalwarebytesTrojan.Downloader
RisingSpyware.Voltar!1.AF1D (CLASSIC)
YandexTrojan.GenAsa!UJ9hKX5WaTE
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Zbot.EQPB!tr
BitDefenderThetaGen:NN.ZexaF.34062.mGX@aiyCSOek
AVGWin32:Susn-AU [Trj]
Paloaltogeneric.ml
MaxSecureTrojan.Malware.4053627.susgen

How to remove Barys.4004?

Barys.4004 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment