Malware

Should I remove “Barys.560”?

Malware Removal

The Barys.560 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.560 virus can do?

  • At least one process apparently crashed during execution
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)

How to determine Barys.560?


File Info:

name: 45A4AF5D850CEA0C8C04.mlw
path: /opt/CAPEv2/storage/binaries/6b0b015fe23bd571c26e6bee0f11509628489224d966dfb9de31a823bae42a0c
crc32: 3E8DE1C0
md5: 45a4af5d850cea0c8c043ff7ba504a66
sha1: 899e36566b5eecd1a9ffc2b5f4c548819934e7db
sha256: 6b0b015fe23bd571c26e6bee0f11509628489224d966dfb9de31a823bae42a0c
sha512: 9cfdd4f50b9aa2cdf4db917c8a3311240a0335bb9cec96b6f32d33146b2b2ce4059da346671d4c97cc61af0e46feb8caf88d58918e23e772d01fcb25bb20f9b5
ssdeep: 3072:HEr7LqZmS4gHvGNiomwoj6lktOUFlup5p+BH8H+fdMyDDccq2nlOtY:kr7LUq8vnoAjJtZFYLM58H+fyyNnaY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15024BF10748298B3F45D493549C418D98BBCEC13BBA6ECFFEF888A4956E81C06C7656F
sha3_384: 3530f1373e6db75df29d2b428ea74bed68832ada171f0a042051b4bb99a7fe7249ec755a16ee3c9693fe129f74a98581
ep_bytes: 6a606850354100e8d3130000bf940000
timestamp: 2012-03-10 21:34:18

Version Info:

0: [No Data]

Barys.560 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Jorik.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Packed.22356
MicroWorld-eScanGen:Variant.Barys.560
FireEyeGeneric.mg.45a4af5d850cea0c
CAT-QuickHealWorm.SlenfBot.Gen
McAfeeTrojan-FACW!45A4AF5D850C
CylanceUnsafe
ZillyaTrojan.Jorik.Win32.62932
SangforExploit.Win32.ShellCode.gen
K7AntiVirusTrojan ( 003ac6b21 )
K7GWTrojan ( 003ac6b21 )
Cybereasonmalicious.d850ce
BitDefenderThetaGen:NN.ZexaF.34294.nuW@aiaqLFmG
CyrenW32/FraudLoad.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.OXF
Paloaltogeneric.ml
ClamAVWin.Malware.Bublik-7340719-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.560
NANO-AntivirusTrojan.Win32.Jorik.ndiig
AvastWin32:Kolab-ABN [Trj]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareGen:Variant.Barys.560
EmsisoftGen:Variant.Barys.560 (B)
ComodoMalware@#2dobhzmzoskcd
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosML/PE-A + Mal/Slenfbot-G
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Barys.560
JiangminTrojan/Jorik.awoj
eGambitUnsafe.AI_Score_100%
AviraWORM/Slenfbot.ajmuz
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.F344D
MicrosoftTrojan:Win32/Bulta!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R22077
Acronissuspicious
ALYacGen:Variant.Barys.560
VBA32BScope.Backdoor.IRC.Bot
MalwarebytesTrojan.Downloader
APEXMalicious
RisingTrojan.Generic@ML.97 (RDML:+YPV5l4xaC5x6N2REyjIZw)
YandexTrojan.GenAsa!2tOz+QKmwEk
IkarusTrojan.Win32.Jorik
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Slenfbot.FE!tr
AVGWin32:Kolab-ABN [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Barys.560?

Barys.560 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment