Malware

Barys.5085 (B) malicious file

Malware Removal

The Barys.5085 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.5085 (B) virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • A process was set to shut the system down when terminated
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

ocsp.verisign.com
crl.verisign.com
csc3-2010-crl.verisign.com
owo-whats-this.duckdns.org

How to determine Barys.5085 (B)?


File Info:

crc32: 2CFEAE72
md5: dfa74ee59c92652b6f2ba083f02d8116
name: poop.exe
sha1: e722908adcad2882b231b5a73a13b0248dd1bb55
sha256: 44dde7121c9c4582c40f02b9024f2f56e344a3d4e1d8d32989afc742ecb28d07
sha512: 50ac97d644f1757be802c659214d104c001b0ba2a0eeee53c6b09fb763ee05b9f294ea86f3746baedefe99ef751aa896237edc70165611138ad6f9ad7abcc282
ssdeep: 3072:/Gzem9MKbGh+NRsxD1G7GoPH3mkl0mOlylll+ilkHmllillll+mNllllsXmlllB:ehNu1G7Geu5bJnD
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Barys.5085 (B) also known as:

MicroWorld-eScanGen:Variant.Barys.5085
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
McAfeePacked-WL!DFA74EE59C92
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Variant.Barys.5085
K7GWTrojan ( 700000121 )
Cybereasonmalicious.59c926
TrendMicroTROJ_GEN.R002C0DDU20
BaiduMSIL.Backdoor.Bladabindi.a
F-ProtW32/Barys.BG.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Packed.Barys-6880522-0
GDataGen:Variant.Barys.5085
KasperskyHEUR:Trojan.Win32.Generic
AlibabaBackdoor:MSIL/Bladabindi.14cd8769
AegisLabTrojan.Win32.Generic.4!c
RisingBackdoor.MSIL.Bladabindi!1.9E49 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Barys.5085 (B)
ComodoMalware@#2351afvrowwee
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.KillProc.54508
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.dfa74ee59c92652b
SophosMal/Bbindi-G
IkarusTrojan.MSIL.Bladabindi
CyrenW32/Barys.BG.gen!Eldorado
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_100%
MicrosoftBackdoor:MSIL/Bladabindi.AJ
ArcabitTrojan.Barys.D13DD
ZoneAlarmHEUR:Trojan.Win32.Generic
AhnLab-V3Trojan/Win32.MSIL.C3285476
Acronissuspicious
ALYacGen:Variant.Barys.5085
MAXmalware (ai score=80)
Ad-AwareGen:Variant.Barys.5085
MalwarebytesBackdoor.LimeRat
ESET-NOD32a variant of MSIL/Bladabindi.LX
TrendMicro-HouseCallTROJ_GEN.R002C0DDU20
TencentWin32.Trojan.Generic.Wvul
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Bladabindi.AS!tr
BitDefenderThetaGen:NN.ZemsilF.34108.jqW@aWg!Ub
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.c96

How to remove Barys.5085 (B)?

Barys.5085 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment