Malware

Barys.6147 removal tips

Malware Removal

The Barys.6147 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.6147 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Barys.6147?


File Info:

name: E82F05EFB23E255BF376.mlw
path: /opt/CAPEv2/storage/binaries/cf592b27b0b65401bdd35a807efc0a8257938e5a77e45925bd551c3f50829027
crc32: D5FA0C43
md5: e82f05efb23e255bf376537dadae7690
sha1: 421c47415e4ae19fc667584e50b2e7eed7c4ec8e
sha256: cf592b27b0b65401bdd35a807efc0a8257938e5a77e45925bd551c3f50829027
sha512: e4e8d5f9f35db922bed25e9595490d928106255d947a8770c980212591386a9212d353cc754eb9af9c2ac319acd7e17e433110bf7a69467e6cf5d56788f2eb0b
ssdeep: 6144:dvVyrhk0mcDJKsyO+07h8eQe12FLY6DmBiC:ryrxlVKsyL07eeU1VCBiC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1831401907FA54CB2FD790F7598F6A90346BDD28228B0227B756004CD2CCF6E24B666DD
sha3_384: 53f0bd25a10c69f5eb27dd897247a19e7729fc1c5f74ea3171836607be872ed5e847472abbccb6d9503a19eb10452c6f
ep_bytes: 558bec83ec1c53ff0d220d8e00a3d10e
timestamp: 2004-08-08 16:40:25

Version Info:

FileDescription: COMODO lnstaller
LegalCopyright: 2005-2010 COMODO. All rights reserved.
ProductName: COMODO lnstaller
CompanyName: CJSC "Computing Forces"
FileVersion: 0.6.4.0
ProductVersion: 1.2.1.7
Translation: 0x0409 0x0000

Barys.6147 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.6147
ClamAVWin.Spyware.Zbot-67955
FireEyeGeneric.mg.e82f05efb23e255b
McAfeePWS-Zbot.gen.agz
Cylanceunsafe
ZillyaTrojan.Zbot.Win32.64234
SangforTrojan.Win32.XPACK.Gen
K7AntiVirusSpyware ( 0029a43a1 )
AlibabaTrojanSpy:Win32/Spyware.bf3b8168
K7GWSpyware ( 0029a43a1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Spy.Zbot.AAO
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.6147
NANO-AntivirusTrojan.Win32.Zbot.belhwl
AvastWin32:Zbot-OUZ [Trj]
TencentMalware.Win32.Gencirc.114e54fd
TACHYONTrojan-Spy/W32.ZBot.204152
EmsisoftGen:Variant.Barys.6147 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.PWS.Panda.2005
VIPREGen:Variant.Barys.6147
McAfee-GW-EditionPWS-Zbot.gen.agz
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.btyu
WebrootW32.Trojan.Genkd
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan[Spy]/Win32.Zbot
MicrosoftPWS:Win32/Zbot!ml
XcitiumMalware@#203ozuh35e71k
ArcabitTrojan.Barys.D1803
ViRobotTrojan.Win32.A.Zbot.204152
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Barys.6147
GoogleDetected
AhnLab-V3Win-Trojan/Zbot.204152
VBA32TrojanSpy.Zbot
ALYacGen:Variant.Barys.6147
MAXmalware (ai score=89)
PandaTrj/Genetic.gen
RisingMalware.Zbot!8.E95E (TFE:1:g1XY1G6lwbB)
YandexTrojanSpy.Zbot!qnIJcbdsuaw
IkarusTrojan-Spy.Win32.Zbot
MaxSecureTrojan.Malware.4228659.susgen
FortinetW32/Shiz.NCF!tr
BitDefenderThetaGen:NN.ZexaF.36662.mu2@aud0Hani
AVGWin32:Zbot-OUZ [Trj]
Cybereasonmalicious.15e4ae
DeepInstinctMALICIOUS

How to remove Barys.6147?

Barys.6147 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment