Malware

Barys.50422 information

Malware Removal

The Barys.50422 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.50422 virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file

How to determine Barys.50422?


File Info:

crc32: 7CFF2131
md5: 7d74497aac14355e57e07e081699dae9
name: 7D74497AAC14355E57E07E081699DAE9.mlw
sha1: 405dfcca4a614cb0836f370d5c53f7b815cb9cfe
sha256: e74748413c5577ab9639b3e46f76b0e344dbc6c1ceed8aff67df622ac833ae74
sha512: c0953f98245d51cee0185d4b1ec70f3ece906613452c327e3cccb1dda149de48b4c16437b86ca3b52b76fd06f29cc3118557a7bc4822ae4d8b370be212ed5e85
ssdeep: 24576:XkJnsEd+pQpmb00TIlXexS/FNscnOY+6yOLSV7:XkJnsEd+GAbFIlXexStNsaO7kSZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2012
InternalName: DynamicDragon
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: DynamicDragon x5e94x7528x7a0bx5e8f
ProductVersion: 1, 0, 0, 1
FileDescription: DynamicDragon Microsoft x57fax7840x7c7bx5e94x7528x7a0bx5e8f
OriginalFilename: DynamicDragon.EXE
Translation: 0x0804 0x04b0

Barys.50422 also known as:

K7AntiVirusTrojan-Downloader ( 004d37621 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop3.61066
CynetMalicious (score: 100)
CAT-QuickHealTrojan.MauvaiseRI.S5255318
ALYacGen:Variant.Barys.50422
CylanceUnsafe
ZillyaTrojan.Reconyc.Win32.13894
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan-Downloader ( 004d37621 )
Cybereasonmalicious.aac143
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.BUF
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Malware.Barys-6840299-0
KasperskyHEUR:Trojan.Win32.Reconyc.gen
BitDefenderGen:Variant.Barys.50422
NANO-AntivirusTrojan.Win32.dxtokf.ecvrhk
MicroWorld-eScanGen:Variant.Barys.50422
TencentMalware.Win32.Gencirc.10b4ae44
Ad-AwareGen:Variant.Barys.50422
SophosML/PE-A + Troj/DwnLdr-YUJ
ComodoTrojWare.Win32.Malex.BHF@7jrvkg
BitDefenderThetaAI:Packer.1AC886CB20
TrendMicroTROJ_GEN.R005C0CG521
McAfee-GW-EditionTrojan-FOEW!7D74497AAC14
FireEyeGeneric.mg.7d74497aac14355e
EmsisoftGen:Variant.Barys.50422 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.dqbrm
AviraHEUR/AGEN.1108860
Antiy-AVLTrojan/Generic.ASMalwS.126C5CA
MicrosoftTrojan:Win32/Malex.gen!H
GridinsoftTrojan.Win32.Downloader.sb!s1
ArcabitTrojan.Barys.DC4F6
ZoneAlarmHEUR:Trojan.Win32.Reconyc.gen
GDataGen:Variant.Barys.50422
AhnLab-V3Trojan/Win32.Reconyc.R225683
McAfeeTrojan-FOEW!7D74497AAC14
MAXmalware (ai score=85)
VBA32BScope.Trojan.Reconyc
MalwarebytesGeneric.Trojan.Injector.DDS
TrendMicro-HouseCallTROJ_GEN.R005C0CG521
RisingDownloader.Agent!1.B5A4 (CLASSIC)
YandexTrojan.GenAsa!9gO9y/2fsj8
IkarusTrojan-Downloader.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.BUF!tr.dldr
AVGWin32:DropperX-gen [Drp]
Qihoo-360HEUR/QVM41.1.70B7.Malware.Gen

How to remove Barys.50422?

Barys.50422 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment