Malware

How to remove “Barys.54007”?

Malware Removal

The Barys.54007 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.54007 virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Barys.54007?


File Info:

crc32: ED76F90E
md5: b2866bcb2ee31b946e5e0e284230656d
name: B2866BCB2EE31B946E5E0E284230656D.mlw
sha1: a5fb8271945a9771214bb0ff5c30f929054cec6c
sha256: 78a315459bbb5817995f3cd57d2bba12be7117c9df10352ec8235a0148233861
sha512: 0dee8116777a795d47302e8f5116693fb4fe79abca206791a78976e3fac0b3889b362ade8d2e37e50788ab198b6fba7b5972fdb2a9f34c12ee28eb6d283e7d57
ssdeep: 384:jYda/Rd7ez4xIe60LcWTAJD2FeviuLqc:XxeIISA9Yeviuf
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2021
Assembly Version: 8.1.1.7900
InternalName: svchost.exe
FileVersion: 8.1.1.7900
CompanyName: Intel Corporation
LegalTrademarks: Copyright 1996 - 2006. Intel Corporation
Comments: Host Process for Windows Services
ProductName: Intel(R) Common User Interface
ProductVersion: 8.1.1.7900
FileDescription: Host Process for Windows Services
OriginalFilename: svchost.exe

Barys.54007 also known as:

K7AntiVirusSpyware ( 0056fa4c1 )
LionicTrojan.Win32.Barys.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Barys.54007
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaTrojan:MSIL/Generic.f83f5af3
K7GWSpyware ( 0056fa4c1 )
Cybereasonmalicious.b2ee31
CyrenW32/Trojan.DIS.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Small.GO
APEXMalicious
AvastMSIL:Crypt-KB [PUP]
BitDefenderGen:Variant.Barys.54007
MicroWorld-eScanGen:Variant.Barys.54007
Ad-AwareGen:Variant.Barys.54007
BitDefenderThetaGen:NN.ZemsilF.34796.bm0@ayBjuin
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.mt
FireEyeGeneric.mg.b2866bcb2ee31b94
EmsisoftGen:Variant.Barys.54007 (B)
MicrosoftRansom:MSIL/Stupid
GDataGen:Variant.Barys.54007
AhnLab-V3Malware/Win32.RL_Generic.C4321917
McAfeeArtemis!B2866BCB2EE3
MAXmalware (ai score=85)
VBA32CIL.StupidStealth.Heur
PandaTrj/GdSda.A
IkarusTrojan.Msil
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
AVGMSIL:Crypt-KB [PUP]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HgIASP8A

How to remove Barys.54007?

Barys.54007 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment