Malware

About “Barys.51875” infection

Malware Removal

The Barys.51875 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.51875 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • The binary likely contains encrypted or compressed data.
  • Behavior consistent with a dropper attempting to download the next stage.
  • Exhibits behavior characteristic of Locky ransomware
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
qujtcfxy.click
ucmssuunh.click
ofrokxoumjgho.xyz
rqfsishlqcfkjf.xyz
nbybwadyhgbxfatb.work
kpxvvjk.biz

How to determine Barys.51875?


File Info:

crc32: 1CA695E6
md5: bd59d181dbcad1e76d521ce83d8e26f3
name: BD59D181DBCAD1E76D521CE83D8E26F3.mlw
sha1: dcef738c59692d0af8269a2e959f88108d7086ba
sha256: 40efe1e4fdbf5920da9ffd37fb6e90406f5c23ee99b12891fd72d583b64ee00a
sha512: 8570cd163a199a51b2ed1487bb1c238f6bfbe25d8e0c794b8e7bb6f240105ab7f93ca2b6614a9594b070b1a18f57720f4b393c3832ad7063badc20513d7bda35
ssdeep: 3072:tSk4S8ZS8e5yh3IsgxSkhWPXUjwrSJp9u7ROD5Vp6/7HsK9cRRsG:th4S8ZMyh4sgxSlXUjwrSJWRO1Vp6/7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

filedescription: Longlines
fileversion: 52.62.58.119
companyname: Reglues Superintendents
Translation: 0x0205 0x0586

Barys.51875 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3976
CynetMalicious (score: 100)
ALYacGen:Variant.Barys.51875
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.1dbcad
BaiduWin32.Trojan.Kryptik.awy
CyrenW32/Locky.BD.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.FZJY
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Autoit.abnhy
BitDefenderGen:Variant.Barys.51875
NANO-AntivirusTrojan.Win32.Autoit.evmsiz
MicroWorld-eScanGen:Variant.Barys.51875
TencentWin32.Trojan.Autoit.Phgj
Ad-AwareGen:Variant.Barys.51875
SophosML/PE-A + Mal/Ransom-EE
ComodoTrojWare.Win32.Ransom.Locky.ALL@6lklyd
BitDefenderThetaGen:NN.ZexaF.34790.juW@a0Y5kCei
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPLOCKY.SMBOS2
McAfee-GW-EditionBehavesLike.Win32.Sivis.cc
FireEyeGeneric.mg.bd59d181dbcad1e7
EmsisoftGen:Variant.Barys.51875 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Autoit.kem
WebrootTrojan.Dropper.Gen
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.22DCD38
MicrosoftRansom:Win32/Locky
AegisLabTrojan.Multi.Generic.4!c
GDataGen:Variant.Barys.51875
AhnLab-V3Trojan/Win32.RL_Autoit.R283737
Acronissuspicious
McAfeeRansomware-FRV!BD59D181DBCA
MAXmalware (ai score=100)
VBA32Trojan.Autoit
MalwarebytesRansom.Locky.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPLOCKY.SMBOS2
RisingTrojan.Generic@ML.100 (RDML:/DMz47YPt2xJ73zUh1Mjbg)
YandexTrojan.GenAsa!b3z1UrdUpjY
IkarusTrojan.SuspectCRC
FortinetW32/Kryptik.FFBI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Worm.AutoIt.HwUBEpsA

How to remove Barys.51875?

Barys.51875 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment