Malware

Barys.60874 malicious file

Malware Removal

The Barys.60874 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.60874 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Barys.60874?


File Info:

name: 5C19D17232812DD8CBB4.mlw
path: /opt/CAPEv2/storage/binaries/cba357d68f51f75b1a0162cb668f85f55586d9fcc8310b651efa0867617deabc
crc32: E3AC3AC7
md5: 5c19d17232812dd8cbb4ec733570f74b
sha1: 0ac175d55ef1492e77211066a70ad8a270d3adce
sha256: cba357d68f51f75b1a0162cb668f85f55586d9fcc8310b651efa0867617deabc
sha512: f8b328de005f8fc50de997d4d8d00c604c6ef93023a56c3f797596c0e0af6c66444fbd8cf47707271714fbe615a2b86f27c9f548c7c6e801d7a7f298c129f0f5
ssdeep: 6144:AgvXMzGXTTjVV4E42i7LdurWPbttyQ7RDiM7ARaKebjZGTypbv8Ag+QLf+/UXi:AgvczYcztQeRtyQHAclZoJ+Qri
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19C8423AF1EC8A98DD11514370578A3C34DA79D303C3DB7D8EE34A6AC8E4692253FB911
sha3_384: 7447f9428f87e0bb6f11c953361bf49b60863adfb0ee13bf1f05bf112b19c5fd38eded06edbe6d8c969fbfeb86dd22fa
ep_bytes: 57c7c774afb4df8d3d5fba581affcf0f
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows(R) NetMeeting(R)
FileVersion: 5.1.2600.5512
InternalName: conf
LegalCopyright: Copyright (C) Microsoft Corporation 1996-1999
LegalTrademarks: Microsoft(R) , Windows(R) and NetMeeting(R) are registered trademarks of Microsoft Corporation in the U.S. and/or other countries.
OriginalFilename: conf.exe
ProductName: Windows® NetMeeting®
ProductVersion: 3.01
Translation: 0x0804 0x04b0

Barys.60874 also known as:

BkavW32.AIDetect.malware2
LionicHeuristic.File.Generic.00×1!p
MicroWorld-eScanGen:Variant.Barys.60874
ClamAVWin.Trojan.Agent-35851
FireEyeGeneric.mg.5c19d17232812dd8
ALYacGen:Variant.Barys.60874
CylanceUnsafe
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.232812
CyrenW32/Bredolab.O.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Hupigon.NTT
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.60874
NANO-AntivirusTrojan.Win32.Inject.bemiqo
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Generic.Kcnw
Ad-AwareGen:Variant.Barys.60874
EmsisoftGen:Variant.Barys.60874 (B)
ComodoTrojWare.Win32.Spy.KeyLogger.~P@19qrg4
DrWebTrojan.Inject.5347
VIPREGen:Variant.Barys.60874
TrendMicroTROJ_SPNR.35C413
McAfee-GW-EditionGeneric Packed.al
Trapminemalicious.high.ml.score
SophosMal/Emogen-E
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.60874
WebrootW32.Bifrose.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASBOL.23E
KingsoftWin32.Heur.KVMH015.a.(kcloud)
ArcabitTrojan.Barys.DEDCA
ViRobotBackdoor.Win32.Hupigon.475283
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Hupigon.C28765
McAfeeGeneric Packed.al
MAXmalware (ai score=84)
VBA32suspected of Trojan-Dropper.Agent.109
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_SPNR.35C413
RisingBackdoor.Win32.Undef.ekn (CLASSIC)
YandexHTML.Redirector.B
IkarusVirus.Win32.Heur
FortinetW32/Hupigon.NTT
BitDefenderThetaAI:Packer.898982991F
AVGWin32:Evo-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Barys.60874?

Barys.60874 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment