Malware

Should I remove “Barys.53474”?

Malware Removal

The Barys.53474 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.53474 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Collects information to fingerprint the system

How to determine Barys.53474?


File Info:

crc32: A0E1C9A3
md5: 780babb4a95ffe167620bc62b2dddada
name: 14.04.18.exe
sha1: 12f81e2289f1df6f611761c5f401f4380821ae98
sha256: fe77c5404a6d2a8b8560cff5b8da3becd79c49e488fd7f25a1cb0d55c8afc0ea
sha512: af210eb2fe522ec665da4a1844bdc90bb4b145d32e4bbdb77d432cb12928422eaddc7a82e2352b2b48dc6fb30d703b1d7f0da38f7ff1fb8880c8548405adc80a
ssdeep: 12288:aNnFsZHltxVdzr3WQex0JpdUv3gvVlAgqQE8wmdBNuv6g:qWZBVZjNeGBC3g9lAniwmd
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 12.14.22.106
InternalName: scjnlgmbj.exe
FileVersion: 12.14.22.106
CompanyName: 5125AOZSMAxyniAtE71304kWx827ex5c3ax827ex827ex827ex827ex827eGNBFZlex5409x513fx543ex30adx3057x7159x827ex827ex9a6cx5409x5c41x5f17x513fx827ex827ex827ex3046x30d0x3087x8349x6771x79c1x30adx30f3x305fx30bfx30bfx30b7x827ex897fx5c414rfx827ex30e7x7159x3070x5e8x5d1x930x915x418x43ex5d3x5e6x5dex30e7x827ex827eWK8952dNPx4f0ax5409x30adx30efx304ex30b7x8349x6771x30bfx30a6x79c1x827ex827ex827eRftkOADqx54e6x827ex54e6x5409x30a6x79c1x3070x79c1x30a6x3070x3087x897fx897fx5a1cx827ex6770x827ex30e7x3087x5e8x5e3x5d4x5eax5d2x5d2x5d3x5eax30b7x30bfx79c1x513fx543eqTArlFx8bf6x30b3x30f3x5e1x5e3x5d9x94dx434x440x434x902x431x5ddx5e9x5d3x6771x30adx513fx5409hm344
ProductName: 5125AOZSMAxyniAtE71304kWx827ex5c3ax827ex827ex827ex827ex827eGNBFZlex5409x513fx543ex30adx3057x7159x827ex827ex9a6cx5409x5c41x5f17x513fx827ex827ex827ex3046x30d0x3087x8349x6771x79c1x30adx30f3x305fx30bfx30bfx30b7x827ex897fx5c414rfx827ex30e7x7159x3070x5e8x5d1x930x915x418x43ex5d3x5e6x5dex30e7x827ex827eWK8952dNPx4f0ax5409x30adx30efx304ex30b7x8349x6771x30bfx30a6x79c1x827ex827ex827eRftkOADqx54e6x827ex54e6x5409x30a6x79c1x3070x79c1x30a6x3070x3087x897fx897fx5a1cx827ex6770x827ex30e7x3087x5e8x5e3x5d4x5eax5d2x5d2x5d3x5eax30b7x30bfx79c1x513fx543eqTArlFx8bf6x30b3x30f3x5e1x5e3x5d9x94dx434x440x434x902x431x5ddx5e9x5d3x6771x30adx513fx5409hm344
ProductVersion: 12.14.22.106
FileDescription: 5125AOZSMAxyniAtE71304kWx827ex5c3ax827ex827ex827ex827ex827eGNBFZlex5409x513fx543ex30adx3057x7159x827ex827ex9a6cx5409x5c41x5f17x513fx827ex827ex827ex3046x30d0x3087x8349x6771x79c1x30adx30f3x305fx30bfx30bfx30b7x827ex897fx5c414rfx827ex30e7x7159x3070x5e8x5d1x930x915x418x43ex5d3x5e6x5dex30e7x827ex827eWK8952dNPx4f0ax5409x30adx30efx304ex30b7x8349x6771x30bfx30a6x79c1x827ex827ex827eRftkOADqx54e6x827ex54e6x5409x30a6x79c1x3070x79c1x30a6x3070x3087x897fx897fx5a1cx827ex6770x827ex30e7x3087x5e8x5e3x5d4x5eax5d2x5d2x5d3x5eax30b7x30bfx79c1x513fx543eqTArlFx8bf6x30b3x30f3x5e1x5e3x5d9x94dx434x440x434x902x431x5ddx5e9x5d3x6771x30adx513fx5409hm344
OriginalFilename: scjnlgmbj.exe

Barys.53474 also known as:

MicroWorld-eScanGen:Variant.Barys.53474
CAT-QuickHealTrojan.MSIL
McAfeeRDN/Generic.grp
VIPRETrojan.Win32.Generic!BT
K7GWTrojan ( 0052750f1 )
K7AntiVirusTrojan ( 0052750f1 )
TrendMicroTROJ_GEN.R014C0WDG18
BaiduWin32.Trojan.WisdomEyes.16070401.9500.9943
NANO-AntivirusTrojan.Win32.Kryptik.faiaqb
SymantecTrojan.Gen.2
TrendMicro-HouseCallTROJ_GEN.R014C0WDG18
AvastWin32:Malware-gen
GDataGen:Variant.Barys.53474
KasperskyHEUR:Trojan.MSIL.Generic
BitDefenderGen:Variant.Barys.53474
AegisLabTroj.Msil.Generic!c
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareGen:Variant.Barys.53474
SophosMal/Generic-S
Comodo.UnclassifiedMalware
F-SecureGen:Variant.Barys.53474
DrWebTrojan.PWS.Steam.12700
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Trojan.gc
EmsisoftGen:Variant.Barys.53474 (B)
IkarusTrojan.MSIL.Crypt
CyrenW32/Trojan.DWCS-2076
WebrootW32.Trojan.Gen
AviraTR/Dropper.MSIL.Gen
Endgamemalicious (high confidence)
ArcabitTrojan.Barys.DD0E2
ZoneAlarmHEUR:Trojan.MSIL.Generic
MicrosoftTrojan:Win32/Occamy.C
ALYacGen:Variant.Barys.53474
AVwareTrojan.Win32.Generic!BT
MAXmalware (ai score=99)
VBA32TScope.Trojan.MSIL
CylanceUnsafe
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.MWP
TencentMsil.Trojan.Generic.Afrn
YandexTrojan.Agent!03wTsIzCLes
SentinelOnestatic engine – malicious
FortinetMSIL/Kryptik.MWP!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikemalicious_confidence_100% (W)
Qihoo-360Win32/Trojan.459

How to remove Barys.53474?

Barys.53474 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment