Trojan

Trojan:Win32/Barys.GMA!MTB (file analysis)

Malware Removal

The Trojan:Win32/Barys.GMA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Barys.GMA!MTB virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Barys.GMA!MTB?


File Info:

name: 5E6DD7487F2395D86994.mlw
path: /opt/CAPEv2/storage/binaries/3b5fd55b2f4368d743a86377927f722515ffe5224319e5910cfd26f75f62e635
crc32: 1D53CD8C
md5: 5e6dd7487f2395d8699457d865cff4f2
sha1: 89f3c2bf929db0cc7cda343b5d8f9a14bb4e3dad
sha256: 3b5fd55b2f4368d743a86377927f722515ffe5224319e5910cfd26f75f62e635
sha512: f09eab721ea0a2a7c3d9d92940c9f0c0c726efe3d8d6e06607bf57a7fd5536141e0093b6bb1dc3acf42350bad787a953d12733301518a8d188e273bf1eff20a1
ssdeep: 12288:EI+W+D/FD9bg+WSi5h6XFRbf0ez0npM4dl0v5Jd1:3+W2FD9bg+Qh6XFRbf0ezEM4dmv5l
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15A94D0A6776CAE16CC7F3377257D76C669C1A92EA939904D54E8830B0123EB780CFE11
sha3_384: 5699a2652b441921d96ad9a084d72ad7032197d3fc9a9380032bd296a0d7860e5de956c29a350375420049aaf7372927
ep_bytes: 40452629101c92ae15cdab3fd78ec385
timestamp: 1971-05-16 00:00:00

Version Info:

CompanyName: Wayne J. Radburn
FileDescription: PE/COFF File Viewer
FileVersion: 0.9.9.0
InternalName: PEview
LegalCopyright: Copyright© 1997-2011 Wayne J. Radburn
OriginalFilename: PEview.exe
ProductName: PEview
ProductVersion: 0.9.9.0
Translation: 0x0409 0x04e4

Trojan:Win32/Barys.GMA!MTB also known as:

BkavW32.AIDetectMalware
AVGWin32:TrojanX-gen [Trj]
Elasticmalicious (high confidence)
DrWebTrojan.PackedENT.192
MicroWorld-eScanGeneric.Dacic.304514EE.A.7C781299
SkyhighBehavesLike.Win32.RAHack.gc
McAfeePacked-FJB!5E6DD7487F23
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.3766585
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0001b3411 )
K7GWTrojan ( 0001b3411 )
Cybereasonmalicious.87f239
BitDefenderThetaGen:NN.ZexaF.36802.B83@aSUsTC
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HHBK
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Razy-9786051-0
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderGeneric.Dacic.304514EE.A.7C781299
NANO-AntivirusTrojan.Win32.PackedENT.fjapfl
AvastWin32:TrojanX-gen [Trj]
EmsisoftGeneric.Dacic.304514EE.A.7C781299 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
VIPREGeneric.Dacic.304514EE.A.7C781299
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.5e6dd7487f2395d8
SophosMal/Inject-GJ
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cttyf
WebrootW32.Trojan.Gen
VaristW32/Dacic.E.gen!Eldorado
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=87)
Antiy-AVLGrayWare/Win32.Kryptik.gifq
Kingsoftmalware.kb.a.997
MicrosoftTrojan:Win32/Barys.GMA!MTB
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitGeneric.Dacic.304514EE.A.7C781299
GDataWin32.Trojan.PSE.109W4IM
GoogleDetected
Acronissuspicious
VBA32Trojan.Khalesi
ALYacGeneric.Dacic.304514EE.A.7C781299
TACHYONTrojan/W32.Selfmod
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
YandexTrojan.Agent!RRuFJhSd6qY
IkarusTrojan.Patched
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Barys.GMA!MTB?

Trojan:Win32/Barys.GMA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment