Malware

About “Barys.431111” infection

Malware Removal

The Barys.431111 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.431111 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Barys.431111?


File Info:

name: 9A5AB6C2B109168224F3.mlw
path: /opt/CAPEv2/storage/binaries/fc669772f9a7d3f6c0f47d48de0d6f15bc019a5ebfa20542e732bac0de66247c
crc32: 9D8AB1C7
md5: 9a5ab6c2b109168224f3822220ba39d2
sha1: dd79141118ead07a995f118f7ac4f994e653d039
sha256: fc669772f9a7d3f6c0f47d48de0d6f15bc019a5ebfa20542e732bac0de66247c
sha512: 820444c4ea6cd05d71433070c2925ec42f50f88026f663bb2dca3c6ddb7ee67e1e408f042d9af0b3924a73bb91dc2e6cd05f16531fe3468b7115d564eacfb291
ssdeep: 768:ffIeSb6IAQJkm8Mb8dRNBRH1+wid+1+j/SD/eZCcLX/CVSFJ0T72Uap53:fweSb9l8Q89H1UbLSLeocTzFJ0T72VpV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A5A33CD571C0E86DC67CED7C23CE86B23CD2A70BB60B5E4F53689F659C16A185720A32
sha3_384: efa59e11875d309e0520aaca79bbb0af60df23117a42fc91f67121801c600478ebdc2c3dfd4e7d01d1726758b15318ef
ep_bytes: 6804124000e8eeffffff000000000000
timestamp: 2012-06-27 08:16:17

Version Info:

0: [No Data]

Barys.431111 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Barys.431111
ClamAVWin.Trojan.Changeup-6169544-0
CAT-QuickHealTrojan.Beebone.D
McAfeeVBObfus.n
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusP2PWorm ( 003bb5c51 )
K7GWP2PWorm ( 003bb5c51 )
Cybereasonmalicious.2b1091
BitDefenderThetaGen:NN.ZevbaF.36196.gmX@aS7Cnfi
VirITTrojan.Win32.Cryptor.F
CyrenW32/Autorun.GW.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AXC
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agent.spto
BitDefenderGen:Variant.Barys.431111
NANO-AntivirusTrojan.Win32.Agent.cqkxkm
AvastWin32:VB-ADMQ [Trj]
TencentTrojan.Win32.Agent.har
TACHYONTrojan/W32.VB-Agent.102400.JJ
EmsisoftGen:Variant.Barys.431111 (B)
BaiduWin32.Worm.Autorun.w
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebWin32.HLLW.Autoruner1.18182
VIPREGen:Variant.Barys.431111
McAfee-GW-EditionBehavesLike.Win32.VBObfus.ct
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.9a5ab6c2b1091682
SophosMal/SillyFDC-Y
IkarusTrojan.Patched
GDataGen:Variant.Barys.431111
JiangminTrojan/Vbobf.b
AviraTR/Patched.Ren.Gen
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.VB.AUB@4ol77w
ArcabitTrojan.Barys.D69407
ZoneAlarmTrojan.Win32.Agent.spto
MicrosoftWorm:Win32/Vobfus.gen!W
GoogleDetected
Acronissuspicious
VBA32Trojan.Agent
ALYacGen:Variant.Barys.431111
MAXmalware (ai score=84)
MalwarebytesGeneric.Worm.AutoRun.DDS
PandaW32/Vobfus.GEW.worm
RisingWorm.Pronny!1.E3EB (CLASSIC)
YandexTrojan.GenAsa!g6s4Rrqy4wo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.C!tr
AVGWin32:VB-ADMQ [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Barys.431111?

Barys.431111 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment