Malware

Barys.97597 (B) removal tips

Malware Removal

The Barys.97597 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.97597 (B) virus can do?

  • Executable code extraction
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Barys.97597 (B)?


File Info:

crc32: BEA02145
md5: 9082100124cb62aa834a0bbf7a397834
name: 9082100124CB62AA834A0BBF7A397834.mlw
sha1: 7b462c6c3cc15a08b6d0bdf97cdcf19df5f3aec4
sha256: bc2801aff3d485d3ed713c37554c4b74cf9f6bf2414d14ec2b738b41b5d1af88
sha512: 483dff7b93ba4fa0e0a0ed6743d241b0795bdf947b082f3579974f2f024a69c647e17bd406fea00f2ca826a2351f0a9da541a35147158104758ad52ac220e8ee
ssdeep: 49152:lBMBTWJepFBZK00YxabrESY0rXuD4j3BOhEP3G:lWBTBHeEH0rAIBaA3G
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: end3
FileVersion: 1.00
CompanyName: noOrg
ProductName: Project1
ProductVersion: 1.00
OriginalFilename: end3.exe

Barys.97597 (B) also known as:

K7AntiVirusTrojan ( 00138e091 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.Barys.97597
CylanceUnsafe
ZillyaDropper.NSIS.Win32.2222
SangforTrojan.Win32.Generic.ky
K7GWTrojan ( 00138e091 )
Cybereasonmalicious.124cb6
CyrenW32/S-92796536!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastFileRepMetagen [Malware]
ClamAVWin.Ransomware.Sodinokibi-9887839-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.97597
NANO-AntivirusTrojan.Win32.GenericKD.dcyuzk
ViRobotTrojan.Win32.Z.Barys.1931374
MicroWorld-eScanGen:Variant.Barys.97597
TencentWin32.Trojan-dropper.Nsis.Hrok
Ad-AwareGen:Variant.Barys.97597
SophosGeneric ML PUA (PUA)
F-SecureHeuristic.HEUR/AGEN.1122441
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WIM21
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.9082100124cb62aa
EmsisoftGen:Variant.Barys.97597 (B)
SentinelOneStatic AI – Malicious PE
Webrootnone
AviraHEUR/AGEN.1122441
KingsoftWin32.Troj.NSIS.s.(kcloud)
MicrosoftTrojan:Win32/Azorult!ml
ArcabitTrojan.Barys.D17D3D
GDataGen:Variant.Barys.97597
AhnLab-V3Adware/Win32.DomaIQ.C233455
McAfeeArtemis!9082100124CB
MAXmalware (ai score=84)
TrendMicro-HouseCallTROJ_GEN.R002C0WIM21
YandexTrojan.DR.NSIS!v6RjbgIPSQc
IkarusTrojan-Dropper.NSIS.Agent
MaxSecureTrojan.Malware.7164915.susgen
FortinetRiskware/Verti
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml

How to remove Barys.97597 (B)?

Barys.97597 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment