Malware

Barys.95268 removal guide

Malware Removal

The Barys.95268 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.95268 virus can do?

  • Unconventionial language used in binary resources: Arabic (Oman)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Barys.95268?


File Info:

name: 836CBBB7001E90BF5C1E.mlw
path: /opt/CAPEv2/storage/binaries/ced4dc14eac628b8daa0120e69c4bd654d01846c51655b5ffee862e66f4718c2
crc32: 82FB9842
md5: 836cbbb7001e90bf5c1e6ab29bdfc76c
sha1: 99ca668c981007402631e75b46952ae383d42a01
sha256: ced4dc14eac628b8daa0120e69c4bd654d01846c51655b5ffee862e66f4718c2
sha512: a880b2f55bef41106b07c3aad227f513fd470e18ac9c3f30ed0b31ff15d2e523398902ba3254faffb289178dbfed747b45ea130092d866afbf2b7a5aa959e166
ssdeep: 49152:p4ayX3fzco+OkLKFdjRpNLDdqqpZnojQa0UuP+zuExphhul8VGsfbBNlzwKMVHFj:p4Zvn31deQa0Hm6kEqiFVrc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E2362347E2DBAE80C17550FEE40F6BF5D1118E22ED759683DAAE3F83F074B10215629A
sha3_384: cbceff2ece6f932ac6cac99791a6a82300ca631b87cd7a2a343b4e147623a1fe29c2920479dbecd38b6e655d0dd30e7c
ep_bytes: 60be0040e1048dbe00d05efb57eb0b90
timestamp: 2009-12-04 13:35:59

Version Info:

0: [No Data]

Barys.95268 also known as:

BkavW32.AIDetectMalware
DrWebTrojan.Siggen8.24573
MicroWorld-eScanGen:Variant.Barys.95268
FireEyeGeneric.mg.836cbbb7001e90bf
ZillyaTrojan.Agent.Win32.1087472
SangforTrojan.Win32.Save.a
Cybereasonmalicious.7001e9
BitDefenderThetaGen:NN.ZexaF.36348.@pGfa8eL3fhG
CyrenW32/Virut.BV.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32WinGo/RanumBot.B
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.95268
AvastWin32:Trojan-gen
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREGen:Variant.Barys.95268
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Barys.95268 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Barys.95268
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan[DDoS]/Win32.Windigo
ArcabitTrojan.Barys.D17424
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/SmokeLoader.FRS!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.MalPe.R265570
VBA32BScope.Trojan.AntiAV
ALYacGen:Variant.Barys.95268
MAXmalware (ai score=81)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingRansom.GandCrypt!8.F33E (TFE:5:Wqv0L86NQBE)
YandexTrojan.GenAsa!m9QhmnaJWJQ
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GRWA!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Barys.95268?

Barys.95268 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment