Trojan

Trojan:Win32/Barys.GMA!MTB removal instruction

Malware Removal

The Trojan:Win32/Barys.GMA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Barys.GMA!MTB virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Barys.GMA!MTB?


File Info:

name: F15680A0ACD7DAD85FA9.mlw
path: /opt/CAPEv2/storage/binaries/04cce8a2b96b249d20f63b08760f7fab3f1a3417b23f5a5ef27ad4ca4e52e87f
crc32: 0512921F
md5: f15680a0acd7dad85fa98283a3087214
sha1: 46508e6a99c0a510ba6158d68f8580364cf7ff80
sha256: 04cce8a2b96b249d20f63b08760f7fab3f1a3417b23f5a5ef27ad4ca4e52e87f
sha512: 50acf65e09557e2aa4b09458a31c5bb6d4e756e27b1b1bb55086665fe2c880abdff32e80d0a0911643e9b8996ccf57b9f3bb2e4065f7956f74f28de70591db37
ssdeep: 6144:vuBcIDlvIPYWYg2S9Jnh6jTFRbf0eN0W7cyqCxSngmMBqfycuPbUl0i5cD5J6K1X:0coIPYEBh6XFRbf0ez0npM4dl0v5Jd1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13B94D096775CBF27CE39B377147AB315F4B1DA1EB5E5A09D2028C31B3212CB6858B242
sha3_384: b159b9d591039488c0124a457f5fa4f0833753b0877643731bf64036100fa8733104b8280abac4b7f0e3d4d9cb17333a
ep_bytes: cac12ad89a989e5f9f49a7ce5d0acf74
timestamp: 1971-05-16 00:00:00

Version Info:

CompanyName: Wayne J. Radburn
FileDescription: PE/COFF File Viewer
FileVersion: 0.9.9.0
InternalName: PEview
LegalCopyright: Copyright© 1997-2011 Wayne J. Radburn
OriginalFilename: PEview.exe
ProductName: PEview
ProductVersion: 0.9.9.0
Translation: 0x0409 0x04e4

Trojan:Win32/Barys.GMA!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Dacic.4!c
tehtrisGeneric.Malware
DrWebTrojan.Siggen24.44412
MicroWorld-eScanGeneric.Dacic.304514EE.A.B6D3FB10
ClamAVWin.Packed.Razy-9786051-0
FireEyeGeneric.mg.f15680a0acd7dad8
SkyhighBehavesLike.Win32.RAHack.gc
ALYacGeneric.Dacic.304514EE.A.B6D3FB10
Cylanceunsafe
ZillyaTrojan.KryptikAGen.Win32.61367
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Copak.2c5d4f51
K7GWTrojan ( 0001b3411 )
K7AntiVirusTrojan ( 0001b3411 )
BitDefenderThetaGen:NN.ZexaF.36744.B83@aSUsTC
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik_AGen.BGV
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.bfqhz
BitDefenderGeneric.Dacic.304514EE.A.B6D3FB10
NANO-AntivirusTrojan.Win32.Kryptik.foobtk
AvastWin32:TrojanX-gen [Trj]
RisingTrojan.Kryptik!1.B34D (CLASSIC)
TACHYONTrojan/W32.Selfmod
EmsisoftGeneric.Dacic.304514EE.A.B6D3FB10 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
VIPREGeneric.Dacic.304514EE.A.B6D3FB10
TrendMicroTROJ_GEN.R002C0DAP24
Trapminesuspicious.low.ml.score
SophosMal/Inject-GJ
IkarusTrojan.Patched
GDataWin32.Trojan.PSE.109W4IM
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Patched.Ren.Gen
Antiy-AVLGrayWare/Win32.Kryptik.gifq
Kingsoftmalware.kb.a.999
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitGeneric.Dacic.304514EE.A.B6D3FB10
ZoneAlarmTrojan.Win32.Copak.bfqhz
MicrosoftTrojan:Win32/Barys.GMA!MTB
VaristW32/Dacic.E.gen!Eldorado
Acronissuspicious
McAfeeTrojan-FVOQ!F15680A0ACD7
MAXmalware (ai score=84)
VBA32Trojan.Khalesi
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DAP24
TencentTrojan.Win32.Kryptik.gify
YandexTrojan.Agent!RRuFJhSd6qY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.a99c0a
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Barys.GMA!MTB?

Trojan:Win32/Barys.GMA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment