Malware

About “Barys.51487” infection

Malware Removal

The Barys.51487 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.51487 virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Barys.51487?


File Info:

name: 931AF8A381540D3A6AB3.mlw
path: /opt/CAPEv2/storage/binaries/af9f052ffafd123a3bf2f296a02567dfab91bac6c9c784fc2174beee1d722c0a
crc32: 1907A54A
md5: 931af8a381540d3a6ab3522beaf55248
sha1: acf4c92710753432548e1a12ad0a8c5c4a4b35cc
sha256: af9f052ffafd123a3bf2f296a02567dfab91bac6c9c784fc2174beee1d722c0a
sha512: d0c61c9b230c505ddc659f5f1b5e58fccf5523893e36ee13ced797f9d6ff147f2645222140802b8a6f56d4584db0c6f25afcf37876e0071cc7d6990281c195ba
ssdeep: 6144:bVzFMAbjbMVvN/9n2p3WcEg1hfR5G0dYrpvjvCa8d+SQMa1waG9VAiCuu/vYpP3J:thLlwlkbV7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C7948D3D689D6A305A72E27FBA84A41AF6808DA337069D2B11C357D14E1F5037FCAD2D
sha3_384: 745d12f4be3aa6c70020ea3bdc4e50f2b619d20ed41de9e98373a549d9ecfbd3206037f66da9a91bae79fb21117a708e
ep_bytes: ff250020400000000000000000000000
timestamp: 2087-06-29 10:03:07

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: sd
FileVersion: 1.0.0.0
InternalName: sd.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: sd.exe
ProductName: sd
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Barys.51487 also known as:

LionicTrojan.MSIL.Crysan.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.51487
FireEyeGeneric.mg.931af8a381540d3a
McAfeeArtemis!931AF8A38154
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058b04d1 )
AlibabaBackdoor:MSIL/Crysan.da867e19
K7GWTrojan ( 0058b04d1 )
Cybereasonmalicious.381540
BitDefenderThetaGen:NN.ZemsilF.34062.zm0@aausBXm
CyrenW32/MSIL_Kryptik.GFJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/GenKryptik.FOCV
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.MSIL.Crysan.gen
BitDefenderGen:Variant.Barys.51487
AvastWin32:RATX-gen [Trj]
TencentMsil.Backdoor.Crysan.Hqbi
Ad-AwareGen:Variant.Barys.51487
SophosMal/Generic-S
ZillyaTrojan.GenKryptik.Win32.112568
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Barys.51487 (B)
IkarusTrojan.MSIL.Krypt
GDataGen:Variant.Barys.51487
AviraTR/Dropper.Gen
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4797756
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.Barys.51487
MAXmalware (ai score=82)
MalwarebytesBackdoor.AsyncRAT
TrendMicro-HouseCallTROJ_GEN.R002H0CKT21
SentinelOneStatic AI – Malicious PE
FortinetMSIL/GenKryptik.FOCV!tr
WebrootW32.Trojan.TR.Dropper
AVGWin32:RATX-gen [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Barys.51487?

Barys.51487 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment