Malware

Barys.57587 (B) removal tips

Malware Removal

The Barys.57587 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.57587 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the njRat malware family

How to determine Barys.57587 (B)?


File Info:

name: 221978F40CD5BEBE1008.mlw
path: /opt/CAPEv2/storage/binaries/e9db440236f8fe05f56fee7b048376aa72934d86f5493dac0417bd6766e1c67a
crc32: D4A080DA
md5: 221978f40cd5bebe10088c1edc3064cd
sha1: 80ee9957ea7be06c080907b3ee71040de3dd48b0
sha256: e9db440236f8fe05f56fee7b048376aa72934d86f5493dac0417bd6766e1c67a
sha512: 40149623f892bf532875b84f03ee0d7c766bba2120f4a1f198b273b09cd31fbbfbb8501bbbf880c331b41dcdd8dc62e09207112c50bc516ffa7e3af7fd659cc8
ssdeep: 12288:CoGvYkTKhSFIpzKhgbCNyNBOLZ8sd6fs755lU/PW6lEmM+42Kg1IuBle6NgQSHFv:CvTKhSWzKheCNZWuEFFKg1IiQEqt6nzm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E0455C83F7C350F0EE8315B415FBA73ADA60B30487269DC7D3543EC66A212D16B3A696
sha3_384: 90107c97c4e2343a7ca950e956258ae5edf7cc528e05b40dd8dc51bd63405f298ed2618bd3ad9a9054dfe091277d58a9
ep_bytes: c3000000000000000000000000000000
timestamp: 2021-06-25 12:47:45

Version Info:

0: [No Data]

Barys.57587 (B) also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.57587
FireEyeGeneric.mg.221978f40cd5bebe
CAT-QuickHealTrojan.GenericFC.S20328680
ALYacGen:Variant.Barys.57587
MalwarebytesMalware.AI.2279202791
BitDefenderGen:Variant.Barys.57587
Cybereasonmalicious.40cd5b
BitDefenderThetaGen:NN.ZexaF.34212.nvW@aytmSjkc
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H0CB422
Paloaltogeneric.ml
ClamAVWin.Dropper.njRAT-7436651-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/FakeUpdate.f1dfc532
ViRobotTrojan.Win32.Z.Bladabindi.1265152
RisingBackdoor.Njrat!1.9E49 (CLOUD)
Ad-AwareGen:Variant.Barys.57587
SophosMal/Generic-S
DrWebBackDoor.Bladabindi.15771
McAfee-GW-EditionBehavesLike.Win32.Upatre.th
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Barys.57587 (B)
APEXMalicious
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=82)
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Barys.57587
CynetMalicious (score: 100)
AhnLab-V3Unwanted/Win.Generic.R448447
VBA32TScope.Trojan.MSIL
CylanceUnsafe
TencentWin32.Trojan.Generic.Hnbd
IkarusTrojan.Win32.Boxedapp
FortinetW32/PossibleThreat
AVGMSIL:Bladabindi-JK [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Barys.57587 (B)?

Barys.57587 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment