Trojan

Trojan:Win32/Barys.GMA!MTB removal guide

Malware Removal

The Trojan:Win32/Barys.GMA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Barys.GMA!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Barys.GMA!MTB?


File Info:

name: FAB26E3B77C39B851AF0.mlw
path: /opt/CAPEv2/storage/binaries/84dd563068f4e6fdcc54011e87b0a5aebd0e60b42f2cec035087a66793769372
crc32: 1804A715
md5: fab26e3b77c39b851af03c2c775cbd86
sha1: eae6fe6965ad491347ee552a89d57fb83b52c26e
sha256: 84dd563068f4e6fdcc54011e87b0a5aebd0e60b42f2cec035087a66793769372
sha512: a55f80cd48a8ca77905826df2f2cdc4590e11e3ad153c5779640be667bf891a2bed6a8c24b7b7cc9a32dbe6a89b9803e8616811e26dd7853376e4c2fe4cca1d2
ssdeep: 3072:SI1ZaRzSu2qZXBvpqWIt1I2FKg1vR6f6NLV4H8aX8u2+3YMvuhCw3BDh:t1Z6zSu7XXqPlKmp8g4HMuBoF53BDh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C314BE4675368DA1EC5CF1B218B81939B147D0D93220A2F533B4BE4FD95DE20DACE2DA
sha3_384: 0352be8c18b3e5f3bba2f81b83e4ced4cdc60fb256944fc652e9db748ee829ad24fef11d7a7a0db720825303ae9ec48a
ep_bytes: 1b8cdc084bd5688f4e04511e8c4739a4
timestamp: 1976-11-05 00:00:00

Version Info:

CompanyName: Wayne J. Radburn
FileDescription: PE/COFF File Viewer
FileVersion: 0.9.9.0
InternalName: PEview
LegalCopyright: Copyright© 1997-2011 Wayne J. Radburn
OriginalFilename: PEview.exe
ProductName: PEview
ProductVersion: 0.9.9.0
Translation: 0x0409 0x04e4

Trojan:Win32/Barys.GMA!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Copak.4!c
MicroWorld-eScanTrojan.GenericKDZ.105113
FireEyeGeneric.mg.fab26e3b77c39b85
CAT-QuickHealTrojan.Barys.S32058459
SkyhighBehavesLike.Win32.Picsys.cc
McAfeeTrojan-FVOQ!FAB26E3B77C3
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0001b3411 )
K7GWTrojan ( 00571f921 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36744.m81@aS09i7l
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HHBK
APEXMalicious
ClamAVWin.Packed.Dridex-9861223-1
KasperskyTrojan.Win32.Copak.biwcu
BitDefenderTrojan.GenericKDZ.105113
NANO-AntivirusTrojan.Win32.Kryptik.foobtk
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Evo-gen [Trj]
RisingTrojan.Kryptik!1.B34D (CLASSIC)
EmsisoftTrojan.GenericKDZ.105113 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.PackedENT.192
VIPRETrojan.GenericKDZ.105113
TrendMicroTROJ_GEN.R03BC0DB224
Trapminemalicious.high.ml.score
SophosMal/Inject-GJ
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.15OPOBR
WebrootW32.Trojan.Gen
VaristW32/Dacic.E.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=85)
Antiy-AVLGrayWare/Win32.Kryptik.gifq
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Generic.D19A99
ZoneAlarmTrojan.Win32.Copak.biwcu
MicrosoftTrojan:Win32/Barys.GMA!MTB
CynetMalicious (score: 100)
Acronissuspicious
VBA32Trojan.Khalesi
ALYacTrojan.GenericKDZ.105113
TACHYONTrojan/W32.Selfmod
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DB224
TencentTrojan.Win32.Kryptik.gify
IkarusTrojan.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.965ad4
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Barys.GMA!MTB?

Trojan:Win32/Barys.GMA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment