Trojan

Trojan:Win32/Barys.GMA!MTB (file analysis)

Malware Removal

The Trojan:Win32/Barys.GMA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Barys.GMA!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Barys.GMA!MTB?


File Info:

name: 48EE2A7DDF789371A527.mlw
path: /opt/CAPEv2/storage/binaries/684e5c3ee9fb74cbc8790bd45e04c47c85cbf637541c1fa190fdac1f00104747
crc32: ED1ECF2B
md5: 48ee2a7ddf789371a527e092553ca207
sha1: 393d314b02935eef1450609341f0bef7de45ae84
sha256: 684e5c3ee9fb74cbc8790bd45e04c47c85cbf637541c1fa190fdac1f00104747
sha512: ee30e74fc5e3f4067d69b549bc7b66c20926bf7625bb742d289cda7b291d3458e1bd056f364a5371295f592c1f85bc977a6903e38d1f814ea5f2cce27f29882c
ssdeep: 12288:Gm0NyXgC87oCNXSN253p80npM4dl0v5Jdm5IFc:GPNywC8kCUN253p8EM4dmv5BFc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T164B4CF45720CDEBFF979273B992A765AEA456BFFEAF9A05FD444830E0552EF2004B100
sha3_384: 9d43e0386b0fd8039a485e99d1220ea7dabddf92d079128638f07ca6d6708032af734370494d24803527fa21a8d33482
ep_bytes: 511a95090143218e0492181fc6d170a5
timestamp: 1976-11-05 00:00:00

Version Info:

CompanyName: Wayne J. Radburn
FileDescription: PE/COFF File Viewer
FileVersion: 0.9.9.0
InternalName: PEview
LegalCopyright: Copyright© 1997-2011 Wayne J. Radburn
OriginalFilename: PEview.exe
ProductName: PEview
ProductVersion: 0.9.9.0
Translation: 0x0409 0x04e4

Trojan:Win32/Barys.GMA!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.105113
CAT-QuickHealTrojan.Barys.S32058459
SkyhighBehavesLike.Win32.RAHack.hc
McAfeeTrojan-FVOQ!48EE2A7DDF78
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.3766585
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0001b3411 )
K7GWTrojan ( 0001b3411 )
Cybereasonmalicious.ddf789
ArcabitTrojan.Generic.D19A99
BitDefenderThetaGen:NN.ZexaF.36802.H83@aS09i7l
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HHBK
APEXMalicious
ClamAVWin.Packed.Razy-9786051-0
KasperskyUDS:Trojan.Win32.Copak.chnyo
BitDefenderTrojan.GenericKDZ.105113
NANO-AntivirusTrojan.Win32.PackedENT.fhvjno
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Kryptik.gify
TACHYONTrojan/W32.Selfmod
EmsisoftTrojan.GenericKDZ.105113 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebTrojan.PackedENT.192
VIPRETrojan.GenericKDZ.105113
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.48ee2a7ddf789371
SophosMal/Inject-GJ
IkarusTrojan.Patched
ALYacTrojan.GenericKDZ.105113
WebrootW32.Trojan.Gen
VaristW32/Dacic.E.gen!Eldorado
AviraTR/Patched.Ren.Gen
Antiy-AVLGrayWare/Win32.Kryptik.gifq
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Barys.GMA!MTB
GDataWin32.Trojan.PSE.109W4IM
CynetMalicious (score: 100)
Acronissuspicious
VBA32Trojan.Khalesi
GoogleDetected
MAXmalware (ai score=84)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
YandexTrojan.Agent!RRuFJhSd6qY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Barys.GMA!MTB?

Trojan:Win32/Barys.GMA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment