Malware

Barys.799 information

Malware Removal

The Barys.799 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.799 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Executed a process and injected code into it, probably while unpacking
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Barys.799?


File Info:

crc32: 6942C001
md5: ebb2fb5c832efa8f77ee63accbb52425
name: EBB2FB5C832EFA8F77EE63ACCBB52425.mlw
sha1: 4e65e0670795962abfb5f838ef603f8f79bd9997
sha256: b27af7728496f8107b781d6931b40854c70603397572974ee59616459b1b3f4c
sha512: 084b9a95de2be218db48589c11689936c1287692eedc1d6b385e21777454c65b4d99be57d7512d39b92ff0a65fbaa3446a241b25b83aba239b2e62a17f81aebb
ssdeep: 6144:W5/Y3KUYCBikInsA7jGki9HdXdYuDXS6pDYSzS3ndKneyEoLV0piLN0rOGT10XI:W5rVkQ7jGki9HdXdYuDXSGDYSzS3ndK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Barys.799 also known as:

K7AntiVirusP2PWorm ( 0055e3e51 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader9.4994
CynetMalicious (score: 100)
ALYacGen:Variant.Barys.799
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.36416
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Blocker.bfd98230
K7GWP2PWorm ( 0055e3e51 )
Cybereasonmalicious.c832ef
CyrenW32/Downloader.C.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/AutoRun.Spy.VB.O
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Zusy-7474200-0
KasperskyTrojan-Ransom.Win32.Blocker.dtaw
BitDefenderGen:Variant.Barys.799
NANO-AntivirusTrojan.Win32.Blocker.ecnznu
MicroWorld-eScanGen:Variant.Barys.799
TencentWin32.Trojan.Blocker.Anpi
Ad-AwareGen:Variant.Barys.799
SophosMal/Generic-S
BitDefenderThetaAI:Packer.D78E306D20
VIPRERiskTool.Win32.ProcessPatcher.Nor!cobra (v) (not malicious)
McAfee-GW-EditionBehavesLike.Win32.VBObfus.fh
FireEyeGeneric.mg.ebb2fb5c832efa8f
EmsisoftGen:Variant.Barys.799 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.183F396
MicrosoftTrojan:Win32/Fareit!ml
GDataGen:Variant.Barys.799
TACHYONRansom/W32.VB-Blocker.335872
AhnLab-V3Trojan/Win32.VB.R107855
McAfeeArtemis!EBB2FB5C832E
MAXmalware (ai score=100)
VBA32Trojan.VB.Motil
PandaGeneric Malware
YandexTrojan.GenAsa!a+D+9cxe/ls
IkarusBackdoor.Win32
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.VBSR!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASOoA

How to remove Barys.799?

Barys.799 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment