Trojan

What is “Trojan:Win32/Barys.GMA!MTB”?

Malware Removal

The Trojan:Win32/Barys.GMA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Barys.GMA!MTB virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Barys.GMA!MTB?


File Info:

name: 1AA48FCD6EC2005E54B9.mlw
path: /opt/CAPEv2/storage/binaries/e16759b540d981149a91ee9b6dd7cc6773c95b3a723de47ca6385cb62712144b
crc32: 4C66482E
md5: 1aa48fcd6ec2005e54b9ab5e5f39c83d
sha1: 01d87ed645f681293aefd0a61cf904b33867aeca
sha256: e16759b540d981149a91ee9b6dd7cc6773c95b3a723de47ca6385cb62712144b
sha512: 6e644da3534332d19703e779a471cfe5332980001847130e1aa2ceda32be9a000dd1ad393e79ee08faf6042a6388e39869553c164cb9f7ebeb310bf5c69e262a
ssdeep: 24576:7+U2QwkI2h6XFRbf0ezEM4dmv5BJtOtEM4dmv5zH8HTXm:6iNo7bf0ezj425zUtj425zHwTXm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FF05CF86724C9E55CE793BFB1A39B2076542AD2EE928F85F6459C30B4652CF790CF230
sha3_384: f845e13d03005dde8e5d57f26039a2bc3acb9a2ebdfd483b779dd20371771bd1d321f84130b024cdd2d2d3939ca3420d
ep_bytes: 9321575bc378e3dcc6a9da4d04eab2f7
timestamp: 1971-05-16 00:00:00

Version Info:

CompanyName: Wayne J. Radburn
FileDescription: PE/COFF File Viewer
FileVersion: 0.9.9.0
InternalName: PEview
LegalCopyright: Copyright© 1997-2011 Wayne J. Radburn
OriginalFilename: PEview.exe
ProductName: PEview
ProductVersion: 0.9.9.0
Translation: 0x0409 0x04e4

Trojan:Win32/Barys.GMA!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.1aa48fcd6ec2005e
SkyhighBehavesLike.Win32.RAHack.cc
McAfeeTrojan-FVOQ!1AA48FCD6EC2
MalwarebytesGeneric.Malware.AI.DDS
VIPREDeepScan:Generic.Dacic.8952383F.A.1D955FDF
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0001b3411 )
K7GWTrojan ( 0001b3411 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitDeepScan:Generic.Dacic.8952383F.A.1D955FDF
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HHBK
APEXMalicious
ClamAVWin.Packed.Razy-9786051-0
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderDeepScan:Generic.Dacic.8952383F.A.1D955FDF
NANO-AntivirusTrojan.Win32.Kryptik.foobtk
MicroWorld-eScanDeepScan:Generic.Dacic.8952383F.A.1D955FDF
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Kryptik.gify
TACHYONTrojan/W32.Selfmod
EmsisoftDeepScan:Generic.Dacic.8952383F.A.1D955FDF (B)
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebTrojan.PackedENT.192
ZillyaTrojan.Kryptik.Win32.3766585
Trapminesuspicious.low.ml.score
SophosMal/Inject-GJ
IkarusTrojan.Patched
JiangminTrojan.Khalesi.aiqm
WebrootW32.Trojan.Gen
VaristW32/Dacic.E.gen!Eldorado
AviraTR/Patched.Ren.Gen
Antiy-AVLGrayWare/Win32.Kryptik.gifq
Kingsoftmalware.kb.a.989
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Barys.GMA!MTB
ZoneAlarmVHO:Trojan.Win32.Copak.gen
GDataWin32.Trojan.PSE.109W4IM
GoogleDetected
Acronissuspicious
VBA32Trojan.Khalesi
ALYacDeepScan:Generic.Dacic.8952383F.A.1D955FDF
MAXmalware (ai score=84)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
YandexTrojan.Agent!RRuFJhSd6qY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.GIFQ!tr
BitDefenderThetaGen:NN.ZexaF.36744.083@aSUsTC
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.645f68
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Barys.GMA!MTB?

Trojan:Win32/Barys.GMA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment