Malware

Should I remove “Barys.431091”?

Malware Removal

The Barys.431091 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.431091 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Barys.431091?


File Info:

name: 98B0F16A8BDE8487C058.mlw
path: /opt/CAPEv2/storage/binaries/db6af8dd9f36fb5d6738d674b73934d62ce40d62cb94464662d340ac10b663b7
crc32: AB43DCA9
md5: 98b0f16a8bde8487c058555e3ea3bdee
sha1: 75fdc4632ba699529298b75adf233b20e99f13f7
sha256: db6af8dd9f36fb5d6738d674b73934d62ce40d62cb94464662d340ac10b663b7
sha512: 27e269fd357474b4382ce617dd1df5c021bc16cc56c5efb057e756d4d7999cf8e0ad4bcf3ff6b1638664615a3a1395f68c0f2ff4b5b3b52c36bb013a6848c81d
ssdeep: 1536:4ZxBxKsZLyJxFdhXgI0TRQP/FY0Y6Y2YkYGYHRHNxtwv4RaoacXcmKdBFa:YxDpCH6QP/uRNBcXc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12193712B778010E7C95846B52DC3B7C715B62A851A273A835A203796FC76E010B7D9FF
sha3_384: 90d80c8d5686b454555c01526cea2b981c703e3e65c916cbb5c27c85c9ee4e7beb026c0c01fceebce374e0e0818ba375
ep_bytes: 68a0124000e8eeffffff000000000000
timestamp: 2011-02-14 09:16:47

Version Info:

Translation: 0x0409 0x04b0
ProductName: HppqWO
FileVersion: 7.58
ProductVersion: 7.58
InternalName: zNaTsa
OriginalFilename: zNaTsa.exe

Barys.431091 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VBKrypt.lkoQ
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.431091
ClamAVWin.Trojan.Changeup-6169544-0
FireEyeGeneric.mg.98b0f16a8bde8487
CAT-QuickHealWorm.VobfusMF.S27814427
McAfeeVBObfus.f
MalwarebytesGeneric.Worm.AutoRun.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 001ff72a1 )
AlibabaMalware:Win32/km_2f9164.None
K7GWTrojan-Downloader ( 001ff72a1 )
Cybereasonmalicious.a8bde8
BaiduWin32.Worm.AutoRun.cj
VirITTrojan.Win32.Generic.ATAM
CyrenW32/VB.BR.gen!Eldorado
SymantecW32.Changeup!gen10
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.ABA
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.VBNA.bsmw
BitDefenderGen:Variant.Barys.431091
NANO-AntivirusTrojan.Win32.AutoRun.covjyr
AvastWin32:VB-RED [Trj]
TencentMalware.Win32.Gencirc.13c8c6f9
TACHYONTrojan/W32.VB-Krypt.94208.E
SophosW32/SillyFDC-FT
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Packed.21430
VIPREGen:Variant.Barys.431091
TrendMicroWORM_VOBFUS.SMIA
McAfee-GW-EditionBehavesLike.Win32.VBObfus.nt
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Barys.431091 (B)
IkarusGen.Variant.VBKrypt
GDataWin32.Worm.Vobfus.MN4Z50
JiangminWorm/VBNA.gzmz
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumPacked.Win32.Krap.BV@2qqlmo
ArcabitTrojan.Barys.D693F3
ViRobotTrojan.Win32.A.VBKrypt.94208.E
ZoneAlarmWorm.Win32.VBNA.bsmw
MicrosoftWorm:Win32/Vobfus.BB
GoogleDetected
AhnLab-V3Trojan/Win32.VBKrypt.R3045
BitDefenderThetaAI:Packer.8D28449720
ALYacGen:Variant.Barys.431091
MAXmalware (ai score=89)
VBA32Trojan.VBRA.010801
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMIA
RisingWorm.VobfusEx!1.99EB (CLASSIC)
YandexTrojan.GenAsa!JB/4NGU7+mE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/AutoRun.XM!worm
AVGWin32:VB-RED [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Barys.431091?

Barys.431091 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment