Malware

About “Barys.99744” infection

Malware Removal

The Barys.99744 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.99744 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Barys.99744?


File Info:

crc32: 1D1B3321
md5: 16eeae4f08d27767f107266d6062a78e
name: 16EEAE4F08D27767F107266D6062A78E.mlw
sha1: a02b232e6ff0631d8434a4bae35a02987070ffac
sha256: b05f6b3d5f1c2108f133e092f2efcc9427abd429a3020684d68967ecf7a61c79
sha512: 01475b53e801f3dd715408bed2c759d81e8064bb4a188de9f0600a752dfff1af343a557deff35a88c653865a547385cfa95261a28dd7e4af9ba17fdeace06ebb
ssdeep: 3072:jrWO3GL50jl7yhKDNFxsSmOqYiWz7fj6f:H7ZOKD7x9mOqYiW7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Barys.99744 also known as:

DrWebTrojan.Siggen5.11354
CynetMalicious (score: 99)
ALYacGen:Variant.Barys.99744
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.7879
SangforTrojan.Win32.AGEN.1023373
Cybereasonmalicious.f08d27
CyrenW32/S-bbbafc52!Eldorado
SymantecTrojan.Ransomlock.Q!g3
ESET-NOD32Win32/LockScreen.AQD
AvastWin32:LockScreen-WF [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.99744
NANO-AntivirusTrojan.Win32.RiskGen.bplzvd
SUPERAntiSpywareTrojan.Agent/Gen-Lockscreen
MicroWorld-eScanGen:Variant.Barys.99744
TencentMalware.Win32.Gencirc.114c07ba
Ad-AwareGen:Variant.Barys.99744
ComodoMalware@#qw8iuxm4ofi9
F-SecureHeuristic.HEUR/AGEN.1130385
VIPRETrojan.Win32.Urausy.ab (v)
McAfee-GW-EditionRansom-FBMD!16EEAE4F08D2
FireEyeGeneric.mg.16eeae4f08d27767
EmsisoftGen:Variant.Barys.99744 (B)
WebrootW32.Rogue.Gen
AviraHEUR/AGEN.1130385
MicrosoftRansom:Win32/Urausy.C
ArcabitTrojan.Barys.D185A0
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Barys.99744
TACHYONTrojan/W32.Foreign.130048.H
AhnLab-V3Trojan/Win32.Foreign.R65649
McAfeeRansom-FBMD!16EEAE4F08D2
MAXmalware (ai score=84)
VBA32TrojanRansom.Urausy
MalwarebytesMalware.AI.1051851118
PandaGeneric Malware
RisingTrojan.Generic@ML.83 (RDMK:dqG2E+7UBZyCBuf5xkdLKQ)
YandexTrojan.Foreign!mKTd1kdNNaU
IkarusTrojan-Ransom.Foreign
AVGWin32:LockScreen-WF [Trj]
Paloaltogeneric.ml

How to remove Barys.99744?

Barys.99744 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment