Trojan

Trojan:Win32/Barys.GMA!MTB malicious file

Malware Removal

The Trojan:Win32/Barys.GMA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Barys.GMA!MTB virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Barys.GMA!MTB?


File Info:

name: CC44F342202920AAD6C2.mlw
path: /opt/CAPEv2/storage/binaries/db8d5688705514e9b01675d31dfb3e294da195506ba5134f0f6c6e9454e23e1b
crc32: 7B09966D
md5: cc44f342202920aad6c2c634811890a2
sha1: 1fce23aefbd3cb22d7d14afb1ffcf0ea20a64813
sha256: db8d5688705514e9b01675d31dfb3e294da195506ba5134f0f6c6e9454e23e1b
sha512: a6ec3d64af50867dc0604801749d0431a563c5fdf599af640d36c430f096629a79242fd15e87cb814c1ec23901018841da58e0f1ef1fcd32a393435844f19419
ssdeep: 3072:ndM1/ikxdXV7AifzlKbWsyUvfl5HOwZXjOvO73ID37tnefVg7gRXLboitn/o:ndBCxVbrAOwZzwOMbhkDRXAit/o
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12C24C015720A7EE4E0D6037B1D5E9696AABEE23903350BAF5433D42E1623D3642FF6C4
sha3_384: 7c069bbba54940c2c5d2675cb3aea27f908501e1b7b44269a023fb505f4b9b1b37a2da97d7289d108fd72b3aa4d011fa
ep_bytes: a801556ef858e1e9fd89d8783fcab0c2
timestamp: 1971-05-16 00:00:00

Version Info:

CompanyName: Wayne J. Radburn
FileDescription: PE/COFF File Viewer
FileVersion: 0.9.9.0
InternalName: PEview
LegalCopyright: Copyright© 1997-2011 Wayne J. Radburn
OriginalFilename: PEview.exe
ProductName: PEview
ProductVersion: 0.9.9.0
Translation: 0x0409 0x04e4

Trojan:Win32/Barys.GMA!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Lazy.439579
FireEyeGeneric.mg.cc44f342202920aa
SkyhighBehavesLike.Win32.Klez.dc
McAfeeTrojan-FVOQ!CC44F3422029
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Lazy.439579
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0001b3411 )
K7GWTrojan ( 00571ed01 )
Cybereasonmalicious.efbd3c
ArcabitTrojan.Lazy.D6B51B
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik_AGen.BGV
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Dridex-9861223-1
KasperskyHEUR:Trojan.Win32.Copak.pef
BitDefenderGen:Variant.Lazy.439579
NANO-AntivirusTrojan.Win32.Kryptik.foobtk
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Kryptik.gify
TACHYONTrojan/W32.Selfmod
SophosMal/Inject-GJ
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.PackedENT.192
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Lazy.439579 (B)
IkarusTrojan.Patched
JiangminTrojan.Khalesi.qke
WebrootW32.Trojan.Gen
VaristW32/Dacic.E.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLGrayWare/Win32.Kryptik.gifq
Kingsoftmalware.kb.a.999
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Barys.GMA!MTB
ZoneAlarmHEUR:Trojan.Win32.Copak.pef
GDataGen:Variant.Lazy.439579
GoogleDetected
AhnLab-V3Packed/Win.FJB.C5538060
BitDefenderThetaGen:NN.ZexaF.36608.n83@au6Updk
ALYacGen:Variant.Lazy.439579
MAXmalware (ai score=89)
VBA32Trojan.Khalesi
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Barys.GMA!MTB?

Trojan:Win32/Barys.GMA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment