Malware

What is “Barys.92242”?

Malware Removal

The Barys.92242 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.92242 virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Anomalous binary characteristics

How to determine Barys.92242?


File Info:

crc32: EEC92257
md5: 84452e3633c40030e72c9375c8a3cacb
name: 84452E3633C40030E72C9375C8A3CACB.mlw
sha1: fe65853ff86e5783c3d70edcbe0771447967ab0c
sha256: f0a5b257f16c4ccff520365ebc143f09ccf233e642bf540b5b90a2bbdb43d5b4
sha512: 519b8af4e4f1bca640b009307fb1528d617c7e00e06159fe30390c80b016f6e34b1391e367953e127d40c70ccb65da8c5ab5d311e6aefe7f2f3ee7de2b4aec7b
ssdeep: 3072:WfaJb/HHzTGsbVY6XfRPLlv3vJMiGndRRBmRKuvZVWrMeX7Y1:Tb/HzTXPJR3v9Gn3X8KsYr7Y
type: PE32+ executable (GUI) x86-64, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2016
InternalName: sqhost.exe
FileVersion: 2.0.0.0
CompanyName: Microsoft Corporation
ProductName: sqhost.exe
ProductVersion: 2.0.0.0
FileDescription: Host Process for Windows Service
OriginalFilename: sqhost.exe
Translation: 0x0409 0x04b0

Barys.92242 also known as:

K7AntiVirusTrojan ( 005735c41 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen11.35280
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Multi
ALYacGen:Variant.Barys.92242
CylanceUnsafe
ZillyaTrojan.CoinMiner.Win64.3521
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win64/CoinMiner.d1c13457
K7GWTrojan ( 005735c41 )
Cybereasonmalicious.633c40
CyrenW64/Coinminer.DB.gen!Eldorado
ESET-NOD32a variant of Win64/CoinMiner.ADG
APEXMalicious
AvastWin64:DropperX-gen [Drp]
ClamAVWin.Trojan.Prometei-9832077-1
KasperskyTrojan.Win32.Agent.xahfrs
BitDefenderGen:Variant.Barys.92242
NANO-AntivirusTrojan.Win64.CoinMiner.iqoljq
MicroWorld-eScanGen:Variant.Barys.92242
TencentWin64.Trojan.Coinminer.Dypx
Ad-AwareGen:Variant.Barys.92242
SophosMal/Generic-R + Troj/Miner-AAZ
ComodoMalware@#3vyxi473jylee
VIPRETrojan.Win32.Generic!BT
TrendMicroCoinminer.Win64.MALXMR.TIAOODFT
McAfee-GW-EditionBehavesLike.Win64.Virut.cc
FireEyeGeneric.mg.84452e3633c40030
EmsisoftGen:Variant.Bulz.400582 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Staser.gxd
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1140127
eGambitUnsafe.AI_Score_83%
MicrosoftTrojan:Script/Phonzy.A!ml
ArcabitTrojan.Bulz.D61CC6
AegisLabTrojan.Win32.Malicious.4!c
ZoneAlarmTrojan.Win32.Agent.xahfrs
GDataGen:Variant.Barys.92242
AhnLab-V3Trojan/Win64.CoinMiner.R357164
McAfeeArtemis!84452E3633C4
MAXmalware (ai score=87)
VBA32Trojan.Script.Phonzy
MalwarebytesTrojan.BitCoinMiner
PandaTrj/RnkBend.A
TrendMicro-HouseCallCoinminer.Win64.MALXMR.TIAOODFT
RisingTrojan.Agent!8.B1E (CLOUD)
YandexTrojan.Agent!pePMUGtt95U
IkarusTrojan.Win64.CoinMiner
FortinetW64/CoinMiner.ADG!tr
AVGWin64:DropperX-gen [Drp]
Paloaltogeneric.ml
Qihoo-360Win64/TrojanDropper.Generic.HgEASREA

How to remove Barys.92242?

Barys.92242 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment