Malware

Should I remove “Barys.83371”?

Malware Removal

The Barys.83371 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.83371 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Barys.83371?


File Info:

name: A3D06E9C5CC5FE5DD7BB.mlw
path: /opt/CAPEv2/storage/binaries/6b66eb06f3fe17c5e9de251bc077c8ba636679601ca443e3a70bccea10643593
crc32: 175992A1
md5: a3d06e9c5cc5fe5dd7bb4241b8db4596
sha1: cf44e6da7e47539cb9d31d5cdebb59b3345dfc09
sha256: 6b66eb06f3fe17c5e9de251bc077c8ba636679601ca443e3a70bccea10643593
sha512: 6404bb65c1e5943c249f3c7be2833913c97616274bb12203899fc1b634c191912d2f1af35ede44b55e53f2482922327090dadb913b328657f60446adab6c3221
ssdeep: 768:zPU7Hzh3T5cia/PtWyMqMtH5GB9AI04dNNWGXlSxDVHtf:zs7HzhD4tW5qE5GD58GQxDpt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11BE34A07F28744F6D42341F00996BBBF8631D6186063C7ADEB84DC7CAD674A17A6D31A
sha3_384: 80c7f9b709239d2be2e4829b35195e134ed5317cdd156ff3b912299f61f7fec65f87099670eb0992457591a2003afca7
ep_bytes: 5589e583ec08c7042402000000ff15dc
timestamp: 2009-02-28 05:28:19

Version Info:

CompanyName: Willmaster Inc.
FileDescription: JAF x64 FiX
FileVersion: 1,0,0,0
LegalCopyright: willmaster@willmaster.at
Translation: 0x0000 0x0000

Barys.83371 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.83371
FireEyeGeneric.mg.a3d06e9c5cc5fe5d
ALYacGen:Variant.Barys.83371
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
SymantecML.Attribute.HighConfidence
APEXMalicious
BitDefenderGen:Variant.Barys.83371
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Barys.83371
SophosML/PE-A
ComodoTrojWare.Win32.TrojanDropper.Agent.a@7fhmg
McAfee-GW-EditionPolyPatch-UPX
EmsisoftGen:Variant.Barys.83371 (B)
JiangminTrojan/BAT.KillWin.a
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.1B8DD6
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Barys.83371
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.UPX.C4817204
Acronissuspicious
McAfeePolyPatch-UPX
MalwarebytesMalware.AI.4058746332
RisingTrojan.Win32.Agent.a (CLASSIC)
YandexTrojan.GenAsa!Q+O4UmmrDn8
SentinelOneStatic AI – Malicious PE
FortinetW32/KillWin.BQ!tr
BitDefenderThetaGen:NN.ZexaF.34062.jm1@amX3Uuu
AVGWin32:Malware-gen
Cybereasonmalicious.c5cc5f
MaxSecureTrojan.Malware.300983.susgen

How to remove Barys.83371?

Barys.83371 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment