Malware

How to remove “Barys.58280”?

Malware Removal

The Barys.58280 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.58280 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Barys.58280?


File Info:

name: 75FF1427EC5B7B625912.mlw
path: /opt/CAPEv2/storage/binaries/007654fac1ff5460a441727a0b58f803a76461133855e003eb7626327a10d825
crc32: D7034458
md5: 75ff1427ec5b7b6259127f2dfff73743
sha1: a6f1fffa78d3a1f8dbf79421432bdffe078283b7
sha256: 007654fac1ff5460a441727a0b58f803a76461133855e003eb7626327a10d825
sha512: da329750e9b26143c7628ad90bfd8e7fedcd9b776180b786d63425bacdfdde9a5f8103d8655946502dbcf8d069e2b14eb39c96730892d64ed75910fd6dda43dc
ssdeep: 24576:zFNgIZwnMOOUl4BVFHla74fr5mYCB/58UyaGOuQ5q3h3gfa:zV5QYCB/a
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B3C5D8035ACF4DE5D9C227B458DB733AA338ED34CA269F7BBE09C02459532D5682670E
sha3_384: 2f37c60bbfd014a778d325d1dab5636f06a898c2fb6d09404929e86425369920fff89c4d1ccb2fc39e1f8882756024a4
ep_bytes: 83ec1cc7042402000000ff1544235300
timestamp: 2018-01-18 12:50:01

Version Info:

CompanyName: zg45ghety4iiadqbdfg zbgsdg nqqgdthy qnfgnh q4wvdfghhdName
FileDescription: xg45hherth5uiafwxg gser ghwwhertg wndtyn w5et.FileDescription
FileVersion: cw45gertdtyjt rtjyh jrtuk first.FileVersion7
InternalName: vgw45gherth8tishrw vserg ttrhetrg rbdrtb r7thwtgest.InternalName
LegalCopyright: fgw54gherg tertb t8ywergdfgh herjhj first.LegalCopyright
LegalTrademarks1: ggwegt0rrtywerf yrtyn y9udfhcvbjh herth first.LegalTrademarks1
LegalTrademarks2: gerg iuhegt ufghn u0icvbnerth gwet first.LegalTrademarks2
OriginalFilename: tgfaserg ergtyrf idfn iqodg afdg gerth first.OriginalFilename
ProductName: huygaerf jowerf ocvbn ow5zxfge erg dftyh first.ProductName
ProductVersion: jr tgrw54gwegrgt h dasgf i u faewgr hptrgyj xcbv pe 6hrtrst.ProductVersion
Translation: 0x0409 0x04e4

Barys.58280 also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.Generic.2!c
tehtrisGeneric.Malware
DrWebTrojan.DownLoad3.65252
MicroWorld-eScanGen:Variant.Barys.58280
FireEyeGeneric.mg.75ff1427ec5b7b62
McAfeeDownloader-FBPE!75FF1427EC5B
CylanceUnsafe
ZillyaDownloader.Tovkater.Win32.752
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 00522c051 )
AlibabaTrojanDownloader:Win32/Tovkater.2a30c77d
K7GWTrojan-Downloader ( 00522c051 )
Cybereasonmalicious.7ec5b7
BitDefenderThetaGen:NN.ZexaF.34582.K!3@aCNBXLgi
CyrenW32/S-5ae627fc!Eldorado
SymantecSMG.Heur!gen
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Tovkater.IE
TrendMicro-HouseCallTROJ_GEN.R002C0OFR22
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderGen:Variant.Barys.58280
NANO-AntivirusRiskware.Win32.TOVus.exejpo
RisingDownloader.Tovkater!8.E5CE (CLOUD)
Ad-AwareGen:Variant.Barys.58280
VIPREGen:Variant.Barys.58280
TrendMicroTROJ_GEN.R002C0OFR22
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Tovkater
GDataGen:Variant.Barys.58280
JiangminAdWare.TOVus.ff
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen7
ViRobotTrojan.Win32.Z.Strictor.2688993.X
MicrosoftTrojan:Win32/Wacatac.B!ml
SentinelOneStatic AI – Malicious PE
AhnLab-V3PUP/Win32.InstallMonster.R218251
Acronissuspicious
VBA32AdWare.TOVus
ALYacGen:Variant.Barys.58280
PandaTrj/Genetic.gen
APEXMalicious
TencentMalware.Win32.Gencirc.10b79ef2
YandexTrojan.GenAsa!6VSSSVb8iec
MAXmalware (ai score=97)
FortinetW32/Tovkater.IE!tr
AVGFileRepMalware [Misc]
AvastFileRepMalware [Misc]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Barys.58280?

Barys.58280 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment