Malware

Barys.87105 malicious file

Malware Removal

The Barys.87105 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.87105 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • Attempts to interact with an Alternate Data Stream (ADS)

How to determine Barys.87105?


File Info:

name: DD473D87E16C103BAB00.mlw
path: /opt/CAPEv2/storage/binaries/d401ce44188503deb7b96d4983506e175c067f3fe939ca52948fc6d06f8651ea
crc32: D104FBF4
md5: dd473d87e16c103bab00b4a7af3142b2
sha1: fb7bfd2176108b2cb87ed28fe712c203bf3942c5
sha256: d401ce44188503deb7b96d4983506e175c067f3fe939ca52948fc6d06f8651ea
sha512: df720dc07ffacfb75704b4ef911600c60bb41caa1c04e6cc89f4baee5a8188fca7f73d08c3092cf159629967a013193e2c6c41bc22d7c3c00671cf222b2b5fa9
ssdeep: 12288:l2+CevMRCebDPyp/a91zGxZYN23XLVnoU+VXIZ:Q+PvBe6qcA2npn2VYZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EBA4238F5358C4F0C93188B069A3663E4D589D3ABD736F63A26534063D399B8A7C21F7
sha3_384: 6fa32c0a0d8e09aa92396b333e7a45e1ef78224f33561bfe39e65caaae71d91eca82b52bb8c47b830809af23224ee0e9
ep_bytes: b800c04f00608da80040f0ff6872efe6
timestamp: 2019-11-24 04:49:56

Version Info:

FileDescription:
FileVersion: 1.1.32.00
InternalName:
LegalCopyright:
OriginalFilename:
ProductName:
ProductVersion: 1.1.32.00
Translation: 0x0409 0x04b0

Barys.87105 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.87105
FireEyeGeneric.mg.dd473d87e16c103b
McAfeeArtemis!DD473D87E16C
SangforTrojan.Win32.Wacatac.C
AlibabaTrojan:Win32/Meterpreter.62abfe83
Cybereasonmalicious.7e16c1
BitDefenderThetaGen:NN.ZexaF.34212.Cm0@auowByoi
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
BitDefenderGen:Variant.Barys.87105
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Barys.87105
EmsisoftGen:Variant.Barys.87105 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Meterpreter
GDataGen:Variant.Barys.87105
AviraTR/Crypt.ZPACK.Gen
ArcabitTrojan.Barys.D15441
MicrosoftTrojan:Win32/Zpevdo.B
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R362088
ALYacGen:Variant.Barys.87105
MAXmalware (ai score=89)
APEXMalicious
RisingTrojan.Generic@AI.96 (RDML:F1kPWoZLBfszkHpQSH05ag)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMalicious_Behavior.SB
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Barys.87105?

Barys.87105 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment