Malware

How to remove “Barys.60053 (B)”?

Malware Removal

The Barys.60053 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.60053 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Loads a driver
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine Barys.60053 (B)?


File Info:

name: BECE616942F5B6B294FE.mlw
path: /opt/CAPEv2/storage/binaries/22b97415c93020220e2fda44670e3eee6275c1f84cd94ddbb2df344232f79067
crc32: A126FF11
md5: bece616942f5b6b294fe2b25f6a5fb39
sha1: f7589257e96e21c801294a6905176c5ca82d40ab
sha256: 22b97415c93020220e2fda44670e3eee6275c1f84cd94ddbb2df344232f79067
sha512: cb5bb471ce640ebb2d1c4971c28b731d2cde1d2a8d6d60a255ec903ed00a3103a90c7de3c9759612cb6f6b00e5391108f4f168de1ef58a255f786e78a63cde83
ssdeep: 49152:dluim8lbvjqd5EZQwcE4Nxce940R/yyEyyV:B9vjqdyZlcE4l940R/yyEyyV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CFF5BF04D063D6BEC439187114EC2B347C3905083956D3E79666FCA56EE3BB396E2AF8
sha3_384: 282f0c5f5193ce86ab782f238990c168f5dec3c7b2e7940cc72e1dfd3991cf0cbbb5c42b8204710c4733492a5193c545
ep_bytes: 558bec6aff68f85c70006814124b0064
timestamp: 2022-04-22 11:53:37

Version Info:

0: [No Data]

Barys.60053 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.60053
FireEyeGeneric.mg.bece616942f5b6b2
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan ( 005246d51 )
BitDefenderGen:Variant.Barys.60053
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.942f5b
ArcabitTrojan.Barys.DEA95
BitDefenderThetaGen:NN.ZexaF.34638.ltW@a035enbb
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/FlyStudio.HackTool.A potentially unwanted
RisingTrojan.Generic@AI.98 (RDMK:cmRtazq6iYu3ApswYq6z3kqRUi36)
Ad-AwareGen:Variant.Barys.60053
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
McAfee-GW-EditionBehavesLike.Win32.VirRansom.wc
EmsisoftGen:Variant.Barys.60053 (B)
APEXMalicious
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.12RRE9
CynetMalicious (score: 100)
VBA32BScope.Trojan.Tiggre
ALYacGen:Variant.Barys.60053
MAXmalware (ai score=86)
MalwarebytesTrojan.MalPack.FlyStudio
IkarusPUA.BlackMoon
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.ELG!tr.pws
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Barys.60053 (B)?

Barys.60053 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment