Malware

Barys.971 information

Malware Removal

The Barys.971 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.971 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

How to determine Barys.971?


File Info:

crc32: E10BABD2
md5: 3a3d98561ea984ef6d3fb7c645b34bc1
name: 3A3D98561EA984EF6D3FB7C645B34BC1.mlw
sha1: ac789aa0bce53f1e1d1fe523c7825285da70b4b8
sha256: c7b1d8fc0f4a4c702a295371b04ea051616e45054a4183632c2ea6c5374028ba
sha512: 2ddd16ae236540a79daaa1bcfba81a97bbd2d5eddd764d804c593991eba8562e95941cdbeb53934a0570cd0051fe251beb4b745fff286d46a1fa11331bc0e614
ssdeep: 12288:a30cj+MV2yCm2iykrRzDww63IaWotUs5P7r9r/+pppppppppppppppppppppppp:ahV3SUs51q
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: hnVKxvrvRSmyghf
Assembly Version: 4.5.8.4
InternalName: ASUN FUD.exe
FileVersion: 4.5.8.4
LegalTrademarks: tEPJxIIVqrCzPEs
ProductName: gHqXdpUwWlgmKuE
ProductVersion: 4.5.8.4
FileDescription:
OriginalFilename: ASUN FUD.exe

Barys.971 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Inject.3481
MicroWorld-eScanGen:Variant.Barys.971
FireEyeGeneric.mg.3a3d98561ea984ef
ALYacGen:Variant.Barys.971
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
BitDefenderGen:Variant.Barys.971
Cybereasonmalicious.61ea98
BitDefenderThetaAI:Packer.C3D890F21F
CyrenW32/Faker.J.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastMSIL:Agent-FI [Trj]
ClamAVWin.Dropper.Napolar-6965181-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/runner.ali1000123
NANO-AntivirusTrojan.Win32.Win32.dcjqck
RisingTrojan.Generic!8.C3 (CLOUD)
Ad-AwareGen:Variant.Barys.971
SophosMal/Generic-S
F-SecureTrojan.TR/Injector.GJ.3
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Barys.971 (B)
IkarusTrojan-Dropper.Small
JiangminTrojan/MSIL.bjr
AviraTR/Injector.GJ.3
MAXmalware (ai score=81)
MicrosoftTrojan:Win32/Wacatac.DC!ml
GridinsoftTrojan.Win32.Gen.se!i
ArcabitTrojan.Barys.971
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Barys.971
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Inject.R10130
McAfeeArtemis!3A3D98561EA9
VBA32CIL.StupidPInvoker-2.Heur
MalwarebytesTrojan.Crypt.MSIL
ESET-NOD32a variant of MSIL/Injector.TF
TencentWin32.Trojan.Generic.Ljuj
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Injector.PE!tr
AVGMSIL:Agent-FI [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Inject.HwMAeykA

How to remove Barys.971?

Barys.971 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment