Malware

Barys.93097 (B) removal instruction

Malware Removal

The Barys.93097 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.93097 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs
  • Unusual version info supplied for binary

How to determine Barys.93097 (B)?


File Info:

name: 2C582056D1F931AEE487.mlw
path: /opt/CAPEv2/storage/binaries/a41ce4144f6dc6b0b195071d29c7d0a2a122077ccb5ab99a4d4f0e0981955dc8
crc32: 8CF73F66
md5: 2c582056d1f931aee487464ce4cd181b
sha1: 7830b4c9e2c23baa512115016ad9897cb4acf22f
sha256: a41ce4144f6dc6b0b195071d29c7d0a2a122077ccb5ab99a4d4f0e0981955dc8
sha512: 401a33f0c6e719940f685e818449697f570a24c9157205f4e75b68c0ddd00c5fb5dd6f95ae0dac7df32bf179c6cd7449a135f8d0424db8e6f063ee9dcd3c1e4e
ssdeep: 49152:J8qsfqnbJx6eIsge/ZsCPI5jNQtzHNDgmKwuDdu4:JsegCCjj29jK7
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T18B75337A497B3E82C9C81DBDAD573507990B12350B60A2AEF46C7191A17CBF024FE19F
sha3_384: 01593bfea7a231dffbd768a971fa9fcc3e65b334e7bd873049ba781140da953f6cd86fc5a4e90ad2d8f3c8882293e100
ep_bytes: 53565755488d35555fe6ff488dbe00e0
timestamp: 2021-10-17 03:44:29

Version Info:

CompanyName:
FileDescription: Windows Service Host
FileVersion: 10.0.18362.0
LegalCopyright: Microsoft Corporation
OriginalFilename: svchost.exe
ProductName: Microsoft Windows OS
ProductVersion: 10.0.18362.0
Translation: 0x0000 0x04b0

Barys.93097 (B) also known as:

LionicTrojan.Win32.Miner.4!c
MicroWorld-eScanGen:Variant.Barys.93097
McAfeeArtemis!2C582056D1F9
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 0055631f1 )
AlibabaRiskWare:Win64/Miners.273423a4
K7GWAdware ( 0055631f1 )
Cybereasonmalicious.6d1f93
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win64/CoinMiner.PO potentially unwanted
APEXMalicious
KasperskyUDS:Trojan.Win32.Miner.gen
BitDefenderGen:Variant.Barys.93097
AvastWin64:CoinminerX-gen [Trj]
TencentWin32.Trojan.Miner.Hsiy
Ad-AwareGen:Variant.Barys.93097
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0WJO21
McAfee-GW-EditionBehavesLike.Win64.Dropper.tc
FireEyeGeneric.mg.2c582056d1f931ae
EmsisoftGen:Variant.Barys.93097 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.93097
JiangminTrojan.Miner.rak
MAXmalware (ai score=80)
ViRobotTrojan.Win32.Z.Barys.1683968
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4718187
Acronissuspicious
ALYacGen:Variant.Barys.93097
VBA32Trojan.Miner
TrendMicro-HouseCallTROJ_GEN.R002C0WJO21
YandexRiskware.BitCoinMiner!HcfYlCy+LqY
IkarusTrojan.Win64.CoinMiner
FortinetAdware/Miner
WebrootW32.Trojan.Gen
AVGWin64:CoinminerX-gen [Trj]
PandaTrj/CI.A

How to remove Barys.93097 (B)?

Barys.93097 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment