Trojan

Trojan:Win32/Barys.GMA!MTB information

Malware Removal

The Trojan:Win32/Barys.GMA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Barys.GMA!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Barys.GMA!MTB?


File Info:

name: ED52CBBC5A1B0479756A.mlw
path: /opt/CAPEv2/storage/binaries/6ca64bf3b9e1def1b2563e2de41fbe53c6d1a4b0177288a6f2465282c6489403
crc32: 1B736ECA
md5: ed52cbbc5a1b0479756af396c5f55851
sha1: e537fb393621aa7a211c5c0072efdc4218875252
sha256: 6ca64bf3b9e1def1b2563e2de41fbe53c6d1a4b0177288a6f2465282c6489403
sha512: f11be0808ffd3ac03f9c823fe49ec34399970a2d26b8c922bda1a10b897ce7dd6ba2a747f1bee7bff18ee2a18d86b78d26fc352a0fd22d6b2c509d5bf9362481
ssdeep: 12288:GrB9MPlpiH26TUKp5Jvi/Tpzgk0npM4dl0v5J:cH2m5d0zgkEM4dmv5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12F84BE83728C5ED7CE722A73DD6EB7459A8ED21A186A604C9C5C8F3E7D12C3785CB160
sha3_384: 4551e1b637c2213f9d5574cfbed5d557b21184aa7788853adffe01dca32a79c5df52530475e4c41bf6a03e2bdf7f8b41
ep_bytes: 0055f11b500c459c55dd7c0d979e14b7
timestamp: 1971-05-16 00:00:00

Version Info:

CompanyName: Wayne J. Radburn
FileDescription: PE/COFF File Viewer
FileVersion: 0.9.9.0
InternalName: PEview
LegalCopyright: Copyright© 1997-2011 Wayne J. Radburn
OriginalFilename: PEview.exe
ProductName: PEview
ProductVersion: 0.9.9.0
Translation: 0x0409 0x04e4

Trojan:Win32/Barys.GMA!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Dacic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanDeepScan:Generic.Dacic.8952383F.A.F2716D6A
SkyhighBehavesLike.Win32.Generic.fc
McAfeeTrojan-FVOQ!ED52CBBC5A1B
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.4413949
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0001b3411 )
AlibabaTrojan:Win32/Barys.043dfd70
K7GWTrojan ( 0001b3411 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitDeepScan:Generic.Dacic.8952383F.A.F2716D6A
BitDefenderThetaGen:NN.ZexaF.36680.y43@aazQJtd
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HHBK
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Razy-9786051-0
KasperskyTrojan.Win32.Copak.apitb
BitDefenderDeepScan:Generic.Dacic.8952383F.A.F2716D6A
NANO-AntivirusTrojan.Win32.Kryptik.foobtk
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Kryptik.gify
EmsisoftDeepScan:Generic.Dacic.8952383F.A.F2716D6A (B)
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebTrojan.Siggen22.41256
VIPREDeepScan:Generic.Dacic.8952383F.A.F2716D6A
TrendMicroTROJ_GEN.R002C0DLH23
SophosMal/Inject-GJ
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
VaristW32/Dacic.E.gen!Eldorado
AviraTR/Patched.Ren.Gen
Antiy-AVLGrayWare/Win32.Kryptik.gifq
KingsoftWin32.Trojan.Copak.apitb
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Barys.GMA!MTB
ZoneAlarmTrojan.Win32.Copak.apitb
GDataWin32.Trojan.PSE.109W4IM
GoogleDetected
ALYacDeepScan:Generic.Dacic.8952383F.A.F2716D6A
TACHYONTrojan/W32.Selfmod
VBA32Trojan.Khalesi
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DLH23
RisingTrojan.Kryptik!1.B34D (CLASSIC)
YandexTrojan.Agent!RRuFJhSd6qY
IkarusTrojan.Patched
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.93621a
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Barys.GMA!MTB?

Trojan:Win32/Barys.GMA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment