Malware

Barys.59243 removal

Malware Removal

The Barys.59243 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.59243 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Barys.59243?


File Info:

crc32: 3B556AE3
md5: a5a4c4a3a27f20ae00a903e034ba4de2
name: A5A4C4A3A27F20AE00A903E034BA4DE2.mlw
sha1: 231d4b34479681c4a634986d3ecd6e49f7319651
sha256: f5e08c466cd97c28b019803655d0ac7232d09d4894b34f348684434b931a4b95
sha512: 295d50987da5f9d6c88d6a6e8b118170109f4ab6cb97554f232700f5c7b082c08411718e5c43ac8f1d59fc18fb87262611f78fd1f97e0ca67e18ce54d45c8a90
ssdeep: 1536:GU7xlWcqDCH9hw4Pvpv08+IuSfH9eszgt8HmZgPRedo3vDLXn6v8:qDS9Ts8eSFeszgt8BPmsrLXn6v8
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2003 - 2011 Nir Sofer
InternalName: NirCmd
FileVersion: 2.65
CompanyName: NirSoft
ProductName: NirCmd
ProductVersion: 2.65
FileDescription: NirCmd
OriginalFilename: NirCmd.exe
Translation: 0x0409 0x04b0

Barys.59243 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004f8bc31 )
Elasticmalicious (high confidence)
CynetMalicious (score: 85)
CAT-QuickHealRansom.Crowti.MUE.A6
ALYacGen:Variant.Barys.59243
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1351764
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojan:Win32/Kryptik.4ccbd6e2
K7GWTrojan ( 004f8bc31 )
Cybereasonmalicious.3a27f2
CyrenW32/Ransom.CJ.gen!Eldorado
SymantecRansom.CryptXXX!g17
ESET-NOD32a variant of Win32/Kryptik.HGEN
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Ransom.Win32.Agent.pef
BitDefenderGen:Variant.Barys.59243
NANO-AntivirusTrojan.Win32.Kryptik.evhepb
MicroWorld-eScanGen:Variant.Barys.59243
TencentMalware.Win32.Gencirc.10b63de0
Ad-AwareGen:Variant.Barys.59243
SophosMal/Generic-S
ComodoMalware@#2oig7kad459qy
BitDefenderThetaGen:NN.ZexaF.34608.gy0@aecu!FnQ
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroRansom_HPCRYPMIC.SM4
McAfee-GW-EditionRansomware-FTK!A5A4C4A3A27F
FireEyeGeneric.mg.a5a4c4a3a27f20ae
EmsisoftGen:Variant.Barys.59243 (B)
AviraHEUR/AGEN.1110705
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Tovicrypt.A
ArcabitTrojan.Barys.DE76B
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Barys.59243
AhnLab-V3Malware/Win32.RL_Generic.R285865
Acronissuspicious
McAfeeRansomware-FTK!A5A4C4A3A27F
MAXmalware (ai score=100)
VBA32BScope.Trojan.Bagsu
MalwarebytesTrojan.Crypt
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPCRYPMIC.SM4
RisingRansom.CryptXXX!8.5DF0 (CLOUD)
YandexTrojan.GenAsa!ao0N/xdCg2Q
IkarusTrojan-Ransom.Tovicrypt
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HxQBgVAA

How to remove Barys.59243?

Barys.59243 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment