Malware

About “Barys.58049” infection

Malware Removal

The Barys.58049 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.58049 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • The binary likely contains encrypted or compressed data.
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
office.dns04.com
a.tomx.xyz
apk36501.flnet.org
ww1.flnet.org

How to determine Barys.58049?


File Info:

crc32: F93F6331
md5: c9938a32831328c9f2d6b3033f4526a7
name: C9938A32831328C9F2D6B3033F4526A7.mlw
sha1: 6ec449c87bffd81e5561502db4ba2f8f8c521dd2
sha256: bbbcce847097e4ddb59d15076f8aa86f51064a5a4a93858e67dec971bd36d007
sha512: 3385283731786e4c4856fc823ebae856c42bada2673fb187e1c3e86982fcc7d2162d673afa0b0226b64e430501ffb061d9945f414e9ad28f575bbbc9d998de7f
ssdeep: 6144:Fyanzt43MBABORTl1zotgUj2V/Ry+++hxg8VAJt:FyanJ48BABqR62VJy+++hpV0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Barys.58049 also known as:

K7AntiVirusTrojan ( 005127921 )
Elasticmalicious (high confidence)
ALYacGen:Variant.Barys.58049
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.56502
SangforTrojan.Win32.Foreign.usrg
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Starter.ali2000005
K7GWTrojan ( 005127921 )
Cybereasonmalicious.283132
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Plead.K
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Foreign.nnnj
BitDefenderGen:Variant.Barys.58049
NANO-AntivirusTrojan.Win32.Harmony.erbhlf
MicroWorld-eScanGen:Variant.Barys.58049
TencentWin32.Trojan.Foreign.Taet
Ad-AwareGen:Variant.Barys.58049
SophosMal/Generic-S
ComodoMalware@#201h0xyn339at
BitDefenderThetaGen:NN.ZexaF.34686.zqW@a8@5Omhn
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_PLEAD.ZAEH-A
McAfee-GW-EditionTrojan-FPCJ!C9938A328313
FireEyeGen:Variant.Barys.58049
EmsisoftGen:Variant.Barys.58049 (B)
MicrosoftTrojan:Win32/Harmony.A!dha
AegisLabTrojan.Win32.Foreign.j!c
ZoneAlarmTrojan-Ransom.Win32.Foreign.nnnj
GDataGen:Variant.Barys.58049
McAfeeTrojan-FPCJ!C9938A328313
MAXmalware (ai score=99)
VBA32TrojanRansom.Foreign
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_PLEAD.ZAEH-A
RisingBackdoor.Plead/APT#BlackTech!1.C444 (CLOUD)
YandexTrojan.Foreign!ZTrOmggBxxY
FortinetGenerik.FSYKPXU!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Barys.58049?

Barys.58049 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment