Malware

Barys.4409 removal guide

Malware Removal

The Barys.4409 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.4409 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Barys.4409?


File Info:

crc32: 2988678D
md5: e0b76ae4dc1e02ba1393b5d6f14286a3
name: E0B76AE4DC1E02BA1393B5D6F14286A3.mlw
sha1: 9902ceb6f9af538960b54797ccbc502f016bd2bd
sha256: 77d5859c1973d0e9aa2d28a0d8cc46ecc6678828b35a728d8c4efebf596fe448
sha512: 0de3dcce58dcf2b190608cc4fbcbcfab0437d5e6b8a648dbfaf5bd3c8539b1bda9456a12553aa6b58efc36ebdb22ee74875d5a769b5e5974ad8dacec69c38cf5
ssdeep: 6144:R2aOs7VRzXl5uigI/6dSB4MCsc4RSbq8tcomGlbDoSeEos:dVR/hF/6dSB5CscQSbqMBlbDFis
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2015
Assembly Version: 7.0.0.0
InternalName: NJRAT 7.exe
FileVersion: 7.0.0.0
CompanyName: Microsoft
ProductName: NJRAT
ProductVersion: 7.0.0.0
FileDescription: NJRAT
OriginalFilename: NJRAT 7.exe

Barys.4409 also known as:

K7AntiVirusTrojan ( 004b0d661 )
Elasticmalicious (high confidence)
DrWebBackDoor.NJRat.355
CynetMalicious (score: 85)
CAT-QuickHealTrojan.MSIL
ALYacGen:Variant.Barys.4409
CylanceUnsafe
ZillyaTrojan.Injector.Win32.572034
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:MSIL/Injector.a8fd4b2b
K7GWTrojan ( 004b0d661 )
Cybereasonmalicious.4dc1e0
TrendMicroTROJ_GEN.R002C0DGB20
CyrenW32/MSIL_Mintluks.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.GHT
APEXMalicious
AvastMSIL:GenMalicious-DTG [Trj]
KasperskyHEUR:Trojan.MSIL.Generic
BitDefenderGen:Variant.Barys.4409
NANO-AntivirusTrojan.Win32.Agent.dyqhui
MicroWorld-eScanGen:Variant.Barys.4409
TencentMsil.Trojan.Generic.Ajlf
Ad-AwareGen:Variant.Barys.4409
ComodoMalware@#7y8a1fz2orqc
F-SecureTrojan.TR/Dropper.Gen
BitDefenderThetaGen:NN.ZemsilF.34196.wq0@aK9zp9l
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
FireEyeGeneric.mg.e0b76ae4dc1e02ba
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
JiangminTrojan.MSIL.komh
WebrootW32.Infostealer.Zeus
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftBackdoor:MSIL/Bladabindi!rfn
ArcabitTrojan.Barys.D1139
AegisLabTrojan.Win32.Generic.mfHu
ZoneAlarmHEUR:Trojan.MSIL.Generic
GDataGen:Variant.Barys.4409
AhnLab-V3Trojan/Win32.Mintluks.C2882356
McAfeeRDN/Generic BackDoor
MAXmalware (ai score=100)
VBA32Trojan.MSIL.gen.c.1
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DGB20
RisingDropper.Generic!8.35E (C64:YzY0Oi1X9PtC0vCg)
YandexTrojan.Agent!iPq9w0RJ+jQ
IkarusTrojan.MSIL.Injector
FortinetMSIL/Kryptik.TR!tr
AVGMSIL:GenMalicious-DTG [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.cac

How to remove Barys.4409?

Barys.4409 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment