Malware

How to remove “Barys.665 (B)”?

Malware Removal

The Barys.665 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.665 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Barys.665 (B)?


File Info:

name: 0A70457451753D8C6291.mlw
path: /opt/CAPEv2/storage/binaries/a3cbadf8d3d0c7ec47479812896cbff17c5afe974d0296df88d11235fadea440
crc32: F6691739
md5: 0a70457451753d8c62910f05a0007d36
sha1: acdb8695beb081d87e25235ff7f91e085ad2249a
sha256: a3cbadf8d3d0c7ec47479812896cbff17c5afe974d0296df88d11235fadea440
sha512: ce8c56290ec77410640760996afa6692cde9a7aa7cae68dc865b7280153420de779d232462c2153a0dee36f2ae217838cf5ae3fd3c583d48b7bd4210961104aa
ssdeep: 768:t4C0Q6SToFjyFQaKJnljRWh6prKnbcuyD7Udg:+P6v6nljRrKnouy8d
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14AD2C09AE9DD015BE0EA06335AFF7E091E50712EE19681195ED8313BFC26A5D6C043E3
sha3_384: 65a53cef3fb1b1a1b86e154173ad52c35cd20d144de079f923b20bb315198c1fa26bc4276438ea7e36c46ca55995233c
ep_bytes: 60be007040008dbe00a0ffff5789e58d
timestamp: 2002-03-02 22:51:25

Version Info:

CompanyName: BitDefender S.R.L.
FileDescription: BitDefender Antivirus Scanner
FileVersion: 13,0,21,1
InternalName: UIScanner
LegalCopyright: Copyright (C) 2010
OriginalFilename: uiscan.exe
ProductName: BitDefender 2010
ProductVersion: 13,0,18,344
Translation: 0x0409 0x04b0

Barys.665 (B) also known as:

BkavW32.AIDetectMalware
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Barys.665
SkyhighBehavesLike.Win32.MoonLight.mc
McAfeeFakeAV-SecurityTool.js
MalwarebytesMachineLearning/Anomalous.100%
VIPREGen:Variant.Barys.665
SangforTrojan.Win32.Kryptik.OMG
K7AntiVirusTrojan ( 0055dd191 )
AlibabaTrojan:Win32/Tedroo.3a77b91e
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.5beb08
VirITTrojan.Win32.Generic.CNXK
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.OMG
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Fakeav-3120
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.665
NANO-AntivirusTrojan.Win32.HmBlocker.dnefp
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.1150e341
EmsisoftGen:Variant.Barys.665 (B)
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.Spambot.9962
ZillyaTrojan.FakeAV.Win32.100088
FireEyeGeneric.mg.0a70457451753d8c
SophosMal/EncPk-ZC
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.665
JiangminTrojan.Generic.hesmz
WebrootW32.Rogue.Gen
VaristW32/S-bdcee22a!Eldorado
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Win32.Menti
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Barys.665
ViRobotTrojan.Win32.A.Menti.28160.I
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftSpammer:Win32/Tedroo.AB
GoogleDetected
AhnLab-V3Trojan/Win32.FakeAV.R5556
BitDefenderThetaGen:NN.ZexaF.36680.bmKfau4UT2hi
MAXmalware (ai score=100)
VBA32Trojan.ExpProc.014
Cylanceunsafe
PandaGeneric Malware
RisingMalware.Undefined!8.C (TFE:5:qmJxYa4fsBE)
YandexTrojan.Kryptik!tVIyZ/gO+n4
IkarusSpamTool.Win32.Tedroo
MaxSecureTrojan.Yakes.dwnc
FortinetW32/BrowHost.KP!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Barys.665 (B)?

Barys.665 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment