Malware

Barys.72840 information

Malware Removal

The Barys.72840 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.72840 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Barys.72840?


File Info:

name: 1077F3FBBE73CA92D79E.mlw
path: /opt/CAPEv2/storage/binaries/9d1536a291980033cbbf58f84931b47140d920f4eab5aa2156659bffa6d06918
crc32: 82EDCC0E
md5: 1077f3fbbe73ca92d79e768151a2c5dc
sha1: 09ec4743d0d9223bd39aeb3eedbdf025b6468f2c
sha256: 9d1536a291980033cbbf58f84931b47140d920f4eab5aa2156659bffa6d06918
sha512: 79854eeca3563f015bb0e11f3568b9bc9bf7beb5f5b8ccbd8ed1b8eca934bfde7f78fd5c00e235581fbad36f5cf1c1f8fb644a4d75916cdbb42d18610d80e45e
ssdeep: 24576:U2gXbwyU05DxG1M7c0YBBxO9vC6iTHibw88ZhOlf3dbzfKr5nbu:gQ8Z7YBBxf6iecj0lf3t+dny
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FD75DF95F6D891CAF61249B700358E60943ABCB75F4539F9E0DD301B8D2B428EBA2D1F
sha3_384: feab030c6001e9b0ceabe458a4ffa87158834579ed6e8e3b0e512efa4b683678da3ed2186a97b183dd5e9c16a7c96f81
ep_bytes: 9068bae37e00c3616f8029f764db3c04
timestamp: 2021-01-15 22:37:53

Version Info:

0: [No Data]

Barys.72840 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Mansabo.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Barys.72840
FireEyeGeneric.mg.1077f3fbbe73ca92
ALYacGen:Variant.Barys.72840
Cylanceunsafe
SangforTrojan.Win32.Mansabo.V1y7
K7AntiVirusAdware ( 005323941 )
AlibabaTrojan:Win32/Mansabo.80316dae
K7GWAdware ( 005323941 )
BitDefenderThetaGen:NN.ZelphiF.36662.KvW@aG2BtUai
CyrenW32/Patched.R.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Adware.MyDiskSu.B
APEXMalicious
KasperskyHEUR:Trojan.Win32.Mansabo.gen
BitDefenderGen:Variant.Barys.72840
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Mansabo.Snkl
EmsisoftGen:Variant.Barys.72840 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREGen:Variant.Barys.72840
TrendMicroTROJ_GEN.R002C0GHT23
McAfee-GW-EditionBehavesLike.Win32.Benjamin.tc
Trapminemalicious.high.ml.score
SophosMal/Generic-S
GDataGen:Variant.Barys.72840
JiangminPacked.Multi.jon
WebrootPua.Downloadmr.Gen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLGrayWare[AdWare]/Win32.MyDiskSu
ArcabitTrojan.Barys.D11C88
ZoneAlarmHEUR:Trojan.Win32.Mansabo.gen
MicrosoftBackdoor:Win32/Bladabindi!ml
CynetMalicious (score: 100)
AhnLab-V3Packed/Win32.RL_MultiPacked.R355667
McAfeeGenericRXAA-FA!1077F3FBBE73
MAXmalware (ai score=85)
VBA32Trojan.Mansabo
MalwarebytesGeneric.Adware.Agent.DDS
PandaTrj/Genetic.gen
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallTROJ_GEN.R002C0GHT23
RisingTrojan.Mansabo!8.E80A (CLOUD)
YandexTrojan.Mansabo!5spWeaMTXUw
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Barys.7284!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Barys.72840?

Barys.72840 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment