Trojan

Trojan:Win32/Barys.GMA!MTB malicious file

Malware Removal

The Trojan:Win32/Barys.GMA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Barys.GMA!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Trojan:Win32/Barys.GMA!MTB?


File Info:

name: DA5857D99F01BCD25841.mlw
path: /opt/CAPEv2/storage/binaries/db4e899a8e9fb06c66c52087cfcc0f782775c2f5fde85ba2badd908f3face45b
crc32: C689CD3D
md5: da5857d99f01bcd25841182b902fb4e7
sha1: 48e507e6cef224ed8c6dc7c6343d393e83be2094
sha256: db4e899a8e9fb06c66c52087cfcc0f782775c2f5fde85ba2badd908f3face45b
sha512: 444448b08e300c36e1033e1f73a71b2edd7015638973bb0d26a99bb4497f1159b9cda4a38e3fd2e91eb2b302ad3e9078e1bdcb1bdb0d68c013a341038c336d74
ssdeep: 6144:6ljYr5dAhJUNRfBL6FU0SuB53BDu0W7cyqCxSngmMBqfycuPbUl0i5j:6er5e0/fBuFUtuB53p80npM4dl0s
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13464CFC532CC0EA6FAF9F4B3276AF342B540BA16A93D9B5E536493CBC466D335683140
sha3_384: ae807d90accb11d7f9ef3902823c221ccacc4c09646309f7a3bbadf2e1ca5b71d03f3d07e876d4f47b76169386437c0b
ep_bytes: 88ae6434d8f7d0b3dd26e9221f658198
timestamp: 1976-11-05 00:00:00

Version Info:

CompanyName: Wayne J. Radburn
FileDescription: PE/COFF File Viewer
FileVersion: 0.9.9.0
InternalName: PEview
LegalCopyright: Copyright© 1997-2011 Wayne J. Radburn
OriginalFilename: PEview.exe
ProductName: PEview
ProductVersion: 0.9.9.0
Translation: 0x0409 0x04e4

Trojan:Win32/Barys.GMA!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.Siggen25.31718
MicroWorld-eScanTrojan.GenericKDZ.105113
ClamAVWin.Packed.Razy-9794901-0
CAT-QuickHealTrojan.Barys.S32058459
SkyhighBehavesLike.Win32.Generic.fc
McAfeeTrojan-FVOQ!DA5857D99F01
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.3766585
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0001b3411 )
K7GWTrojan ( 0001b3411 )
Cybereasonmalicious.6cef22
BitDefenderThetaGen:NN.ZexaF.36744.u83@aS09i7l
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HHBK
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderTrojan.GenericKDZ.105113
NANO-AntivirusTrojan.Win32.Kryptik.foobtk
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Kryptik.gify
EmsisoftTrojan.GenericKDZ.105113 (B)
F-SecureTrojan.TR/Dropper.Gen
VIPRETrojan.GenericKDZ.105113
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.da5857d99f01bcd2
SophosMal/Inject-GJ
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.109W4IM
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=86)
Antiy-AVLGrayWare/Win32.Kryptik.gifq
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Generic.D19A99
ZoneAlarmVHO:Trojan.Win32.Copak.gen
MicrosoftTrojan:Win32/Barys.GMA!MTB
VaristW32/Dacic.E.gen!Eldorado
AhnLab-V3Trojan/Win.FVOQ.R628622
Acronissuspicious
VBA32Trojan.Khalesi
ALYacTrojan.GenericKDZ.105113
TACHYONTrojan/W32.Selfmod
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
IkarusTrojan.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Barys.GMA!MTB?

Trojan:Win32/Barys.GMA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment