Malware

About “Barys.62606” infection

Malware Removal

The Barys.62606 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.62606 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Authenticode signature is invalid

How to determine Barys.62606?


File Info:

name: 997957A049BEA8F6E242.mlw
path: /opt/CAPEv2/storage/binaries/3702026d9d5e3191022e48c2b537562b57b30b1953c06e83d207d756d0dcb6ad
crc32: 1EF4EB75
md5: 997957a049bea8f6e242c2d057be851a
sha1: f55e5470fcd5a0ad124f4d11af3d11e8167e2ba1
sha256: 3702026d9d5e3191022e48c2b537562b57b30b1953c06e83d207d756d0dcb6ad
sha512: 716ac38fd7f46678c8e6b2f2a09f33bea56d56152f7a9520ea41c5548127e8bf5c4eb90e7459a2aa3b596b8e669d6037279f92435b2f9e04f8f1aa236ec63cfc
ssdeep: 3072:BqxcC0U7fiQUShCXJSiNitKV+dUHhRF9014ulGQeHmsXIN8hXiuSKB1ZHWTeZYZx:JT4ShRF9ulG0sYNOpBrW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17D74063E28BD062BC9B4C6B5CFE68537F020E96B31122A3A98D357594757E4329C353E
sha3_384: ea46d365401b60d2996853244011480d0144ae558a3c4176a6cb63d9c7b00019e9769efea3f10c96fa50048434c0092b
ep_bytes: 6850144000e8eeffffff000000000000
timestamp: 2011-09-19 17:18:27

Version Info:

Translation: 0x0409 0x04b0
Comments: SiDENYSwLfyRMB
CompanyName: PqecVolHdCHE
FileDescription: AMbIa
LegalCopyright: gQkuedQC
ProductName: fJQVmqskJZQBjlF
FileVersion: 1.00
ProductVersion: 1.00
InternalName: windows
OriginalFilename: windows.pif

Barys.62606 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Botnetlog.2088
MicroWorld-eScanGen:Variant.Barys.62606
FireEyeGeneric.mg.997957a049bea8f6
SkyhighGeneric VB.fl
ALYacGen:Variant.Barys.62606
MalwarebytesRemtasu.Spyware.Stealer.DDS
VIPREGen:Variant.Barys.62606
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Barys.62606
BitDefenderThetaGen:NN.ZevbaF.36792.wm0@aux09cji
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Remtasu.J
APEXMalicious
ClamAVWin.Trojan.Spyeye-7591981-0
KasperskyTrojan.Win32.VBKrypt.vini
AlibabaTrojan:Win32/VBKrypt.2c51c040
NANO-AntivirusTrojan.Win32.VB.gxecu
RisingMalware.Undefined!8.C (TFE:5:AhSVPtRnhZJ)
SophosTroj/VB-JHN
GoogleDetected
F-SecureTrojan.TR/Dropper.Gen
ZillyaTrojan.Remtasu.Win32.5400
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Barys.62606 (B)
IkarusTrojan.Win32.Zmunik
WebrootW32.Malware.Gen
VaristW32/VBInject.AZ.gen!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.Bredolab
KingsoftWin32.Trojan.Generic.a
MicrosoftVirTool:Win32/VBInject.RT
XcitiumMalware@#2lpuaeuxei11v
ArcabitTrojan.Barys.DF48E
ZoneAlarmTrojan.Win32.VBKrypt.vini
GDataGen:Variant.Barys.62606
CynetMalicious (score: 99)
McAfeeGeneric VB.fl
DeepInstinctMALICIOUS
VBA32Trojan.VB.Levelup
Cylanceunsafe
PandaGeneric Malware
TencentWin32.Trojan.Vbkrypt.Fdhl
YandexTrojan.Remtasu!AtopPHoO420
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/VBObfus.C!tr
AVGWin32:GenMalicious-KLD [Trj]
Cybereasonmalicious.0fcd5a
AvastWin32:GenMalicious-KLD [Trj]

How to remove Barys.62606?

Barys.62606 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment