Malware

How to remove “Barys.606”?

Malware Removal

The Barys.606 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.606 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Barys.606?


File Info:

name: B6DA7B0F93770CA0BD82.mlw
path: /opt/CAPEv2/storage/binaries/a5d50d0bab8c1355a9a2f105921c405930dde0bbc18269c099f6a6d7b0be7d37
crc32: D039E1D7
md5: b6da7b0f93770ca0bd823ecc3c8b7abe
sha1: 8b2a39d5c91e3b5772609695d97a5a8205941fb8
sha256: a5d50d0bab8c1355a9a2f105921c405930dde0bbc18269c099f6a6d7b0be7d37
sha512: fcb1e07d1bc96f890dc21b32294039c39d4feb067ce62a6111a3d46a267cb19b738c9889e05623208168f57a47348f325db13e2c4100ba49cdbfdbe8a5bc803d
ssdeep: 3072:f5EBoeuHCRHQG9D29uvGzeKNh66cWZPC59x7HZFRLlYnpFH:f5yoQVQG89AGze+xkxLlYnpF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T181148F629971BB16E915093817A06BFA001D3C2F47E9030DBCADDE5F3353DAA34AF942
sha3_384: c5c53102d9d8ed5a04aaaeddc7c74e800b348374c112e21fe52d6b79bc74f44d2499689571d4c4941224ccb8ffabcfea
ep_bytes: 68c0914200e8f0ffffff000000000000
timestamp: 2019-01-12 12:27:37

Version Info:

0: [No Data]

Barys.606 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.606
FireEyeGeneric.mg.b6da7b0f93770ca0
ALYacGen:Variant.Barys.606
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004d83031 )
K7AntiVirusTrojan ( 004d83031 )
BitDefenderThetaGen:NN.ZevbaF.34294.lmW@aW6yyuoG
CyrenW32/VB.QG.gen!Eldorado
ESET-NOD32a variant of Win32/VBClone.E
CynetMalicious (score: 100)
KasperskyTrojan.Win32.VB.dosb
BitDefenderGen:Variant.Barys.606
NANO-AntivirusTrojan.Win32.VB.hfuttk
AvastWin32:VB-AJKU [Trj]
TencentTrojan.Win32.Vb.b
Ad-AwareGen:Variant.Barys.606
SophosML/PE-A + Mal/VB-AQT
ComodoTrojWare.Win32.VBClone.B@88ji29
DrWebTrojan.MulDrop9.358
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Barys.606 (B)
APEXMalicious
JiangminTrojan.VB.aqyg
AviraTR/Patched.Ren.Gen
ArcabitTrojan.Barys.606
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win32.Agent.R252862
McAfeeGenericRXQU-KN!B6DA7B0F9377
MAXmalware (ai score=83)
VBA32SScope.Trojan.VB
MalwarebytesTrojan.Dropper
RisingTrojan.VBClone!1.B5C7 (CLASSIC)
IkarusTrojan.VB.VBClone
eGambitUnsafe.AI_Score_99%
FortinetW32/VBClone.D!tr
AVGWin32:VB-AJKU [Trj]

How to remove Barys.606?

Barys.606 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment