Trojan

Trojan:Win32/Barys.GMA!MTB information

Malware Removal

The Trojan:Win32/Barys.GMA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Barys.GMA!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Barys.GMA!MTB?


File Info:

name: C5387771AAB3AE08B146.mlw
path: /opt/CAPEv2/storage/binaries/53b989fac6168fbecf7657993d544ce82f1477dbd3d74a719ef8f5f17377db60
crc32: 2D66E5C4
md5: c5387771aab3ae08b14613e2bd8a64e5
sha1: 46841be84f4f997de2e1aff216dadbaebb714fa1
sha256: 53b989fac6168fbecf7657993d544ce82f1477dbd3d74a719ef8f5f17377db60
sha512: 5d364fcae1a8027e7417cb9c797135eab2854564c902a1f354ea73b762d8edc1b522885ef10230a870e83fe1bd4ef8228f18bf4bd1f8a657523217555c2edd1a
ssdeep: 3072:uWfYk4203mr0ls0RuF8eVNt1aX2p8htrIWQUJdpXiivhCw3BDh:okO3Bls06ZX2/0WQUTpXB53BDh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C914B081F172CF61C9E923F3246A0E8DBD962425AFB9E2577175338EAA1751C7F27200
sha3_384: 58097cdd4ea465c4a10e79bc2568917ab54dcf10881ab34f982b0b9031a2500f86df959e7dd76c68471c20159fd5e5fc
ep_bytes: a20d954df25421caf785185b35c670e1
timestamp: 1976-11-05 00:00:00

Version Info:

CompanyName: Wayne J. Radburn
FileDescription: PE/COFF File Viewer
FileVersion: 0.9.9.0
InternalName: PEview
LegalCopyright: Copyright© 1997-2011 Wayne J. Radburn
OriginalFilename: PEview.exe
ProductName: PEview
ProductVersion: 0.9.9.0
Translation: 0x0409 0x04e4

Trojan:Win32/Barys.GMA!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.105113
ClamAVWin.Packed.Dridex-9861223-1
FireEyeGeneric.mg.c5387771aab3ae08
CAT-QuickHealTrojan.Barys.S32058459
SkyhighBehavesLike.Win32.Generic.cc
McAfeeTrojan-FVOQ!C5387771AAB3
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0001b3411 )
K7GWTrojan ( 00571f921 )
Cybereasonmalicious.84f4f9
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HHBK
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderTrojan.GenericKDZ.105113
NANO-AntivirusTrojan.Win32.Kryptik.foobtk
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Kryptik.gifyb
TACHYONTrojan/W32.Selfmod
EmsisoftTrojan.GenericKDZ.105113 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPRETrojan.GenericKDZ.105113
Trapminemalicious.high.ml.score
SophosMal/Inject-GJ
IkarusTrojan.Patched
GDataWin32.Trojan.PSE.15OPOBR
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Crypt.XPACK.Gen
Antiy-AVLGrayWare/Win32.Kryptik.gifq
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Generic.D19A99
ZoneAlarmVHO:Trojan.Win32.Copak.gen
MicrosoftTrojan:Win32/Barys.GMA!MTB
VaristW32/Dacic.E.gen!Eldorado
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36744.m81@aS09i7l
ALYacTrojan.GenericKDZ.105113
MAXmalware (ai score=81)
VBA32Trojan.Khalesi
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Barys.GMA!MTB?

Trojan:Win32/Barys.GMA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment