Trojan

Trojan:Win32/Barys.GMA!MTB (file analysis)

Malware Removal

The Trojan:Win32/Barys.GMA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Barys.GMA!MTB virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Barys.GMA!MTB?


File Info:

name: 578A9C89C617CB2E381E.mlw
path: /opt/CAPEv2/storage/binaries/6294081db54dfbf51184f8dc73bb5700585926d00503e679f49c7ccaf04baf43
crc32: 20CD5787
md5: 578a9c89c617cb2e381e740a6cfe18df
sha1: 076f020d4e3ca57cab211178bbd1bbea0e8d0d21
sha256: 6294081db54dfbf51184f8dc73bb5700585926d00503e679f49c7ccaf04baf43
sha512: 459ad2935bddaf3b79d6a4ef6fbc48de591ef0af3187b01802e869ab19025e2f06cc4eca3a75b93bdd5df9cddb2530eee7345a0f67f21bcdbf9421240b6b6d78
ssdeep: 6144:JYC0ly0ANUSV/s8DBLq53BDu0W7cyqCxSngmMBqfycuPbUl0i5cD5J6K1mx12O/F:p0qM53p80npM4dl0v5Jdm5IFc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CFB4DF92B20DEFE3DEB5E77F0E5A73596543893EFB34A86E5454830A4116FF2418B220
sha3_384: 1298e6071e2c4e2ecc291cf8646548db9d260135a929bf7668529cd45f674592ffb149bff83aa0932c4ccc38a77d5f73
ep_bytes: b2dc2c03e2859884e754a1152517c9af
timestamp: 1976-11-05 00:00:00

Version Info:

CompanyName: Wayne J. Radburn
FileDescription: PE/COFF File Viewer
FileVersion: 0.9.9.0
InternalName: PEview
LegalCopyright: Copyright© 1997-2011 Wayne J. Radburn
OriginalFilename: PEview.exe
ProductName: PEview
ProductVersion: 0.9.9.0
Translation: 0x0409 0x04e4

Trojan:Win32/Barys.GMA!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Dacic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.105113
FireEyeGeneric.mg.578a9c89c617cb2e
CAT-QuickHealTrojan.Barys.S32058459
SkyhighBehavesLike.Win32.Generic.hc
ALYacTrojan.GenericKDZ.105113
Cylanceunsafe
ZillyaTrojan.Copak.Win32.188147
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0001b3411 )
AlibabaTrojan:Win32/Barys.9bc415e4
K7GWTrojan ( 0001b3411 )
Cybereasonmalicious.d4e3ca
ArcabitTrojan.Generic.D19A99
BitDefenderThetaGen:NN.ZexaF.36680.H83@aS09i7l
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HHBK
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Razy-9786051-0
KasperskyTrojan.Win32.Copak.aqsxc
BitDefenderTrojan.GenericKDZ.105113
NANO-AntivirusTrojan.Win32.Kryptik.foobtk
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Kryptik.gify
TACHYONTrojan/W32.Selfmod
EmsisoftTrojan.GenericKDZ.105113 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebTrojan.PackedENT.192
VIPRETrojan.GenericKDZ.105113
TrendMicroTROJ_GEN.R002C0DLM23
SophosMal/Inject-GJ
IkarusTrojan.Patched
WebrootW32.Trojan.Gen
VaristW32/Dacic.E.gen!Eldorado
AviraTR/Patched.Ren.Gen
Antiy-AVLGrayWare/Win32.Kryptik.gifq
Kingsoftmalware.kb.a.999
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Barys.GMA!MTB
ZoneAlarmTrojan.Win32.Copak.aqsxc
GDataWin32.Trojan.PSE.109W4IM
GoogleDetected
Acronissuspicious
McAfeeTrojan-FVOQ!578A9C89C617
MAXmalware (ai score=81)
VBA32Trojan.Khalesi
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DLM23
RisingTrojan.Kryptik!1.B34D (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Dridex.584E!dam
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Barys.GMA!MTB?

Trojan:Win32/Barys.GMA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment