Malware

Should I remove “Barys.85264”?

Malware Removal

The Barys.85264 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.85264 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
gclarke7.gotdns.ch
a.tomx.xyz
edgedl.me.gvt1.com
update.googleapis.com

How to determine Barys.85264?


File Info:

crc32: A9826B69
md5: f4dcd7b6f9639ffaff05c8538c4bd57b
name: F4DCD7B6F9639FFAFF05C8538C4BD57B.mlw
sha1: e0c0a9752cf7d69be08418ce9fc17e869ccbd381
sha256: 2c52d43fd22c8cf1db3497fa1d3de9350ff6d8df0c5c8b491301ea959e89a1e0
sha512: cdb4d1bcd55a2ffdeadf401b0bcb11f416ea19da9e9f22c56f9767de5cabc93f6cb9a52c3c7987d83cda8c1d5430bc59de2a7600bba9634c36d27f49ddc97bcf
ssdeep: 24576:ieamoHbYBbXsyWYzb0cWJvfqyPcJohawO4T:ieamTBIM6JvffPrhaS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Barys.85264 also known as:

BkavW32.AIDetect.malware1
LionicHacktool.Win32.BypassUAC.3!c
Elasticmalicious (high confidence)
DrWebBackDoor.Remcos.1
ClamAVWin.Malware.Nymeria-7000772-0
ALYacGen:Variant.Barys.85264
CylanceUnsafe
ZillyaTrojan.AutoIT.Win32.153117
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaPacked:Win32/BypassUAC.e97f3ef4
K7GWTrojan ( 0055aa5f1 )
K7AntiVirusTrojan ( 0055aa5f1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.AutoIt.SN
ZonerProbably Heur.ExeHeaderP
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyExploit.Win32.BypassUAC.llj
BitDefenderGen:Variant.Barys.85264
NANO-AntivirusExploit.Win32.BypassUAC.fckzza
MicroWorld-eScanGen:Variant.Barys.85264
TencentWin32.Exploit.Bypassuac.Eerc
Ad-AwareGen:Variant.Barys.85264
SophosMal/Generic-S
BitDefenderThetaAI:Packer.2C13F04516
TrendMicroTROJ_HPUTOTI.SMQ
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.f4dcd7b6f9639ffa
EmsisoftGen:Variant.Barys.85264 (B)
AviraDR/AutoIt.Gen8
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.262420B
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Barys.85264
McAfeeArtemis!F4DCD7B6F963
MAXmalware (ai score=98)
VBA32Exploit.BypassUAC
MalwarebytesMalware.AI.2370455414
PandaTrj/CI.A
IkarusTrojan.Win32.Autoit
MaxSecureTrojan.Malware.11968513.susgen
FortinetAutoit/Agent.SYM!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Barys.85264?

Barys.85264 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment