Trojan

Trojan:Win32/Barys.GMA!MTB removal instruction

Malware Removal

The Trojan:Win32/Barys.GMA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Barys.GMA!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Barys.GMA!MTB?


File Info:

name: EC2B52A7A83FBAA1F27B.mlw
path: /opt/CAPEv2/storage/binaries/dd9e4911ce77652fa34948fa37592356a8ed980fefa6104dcf5a9d7c52912cae
crc32: 4A986B63
md5: ec2b52a7a83fbaa1f27bb2c723f3677e
sha1: e6fbcd0edecc67774aed34b679497a59f7c1e1b5
sha256: dd9e4911ce77652fa34948fa37592356a8ed980fefa6104dcf5a9d7c52912cae
sha512: acf4e35b5e60ed7516e0cefa543b3616af005ba1d86e6a60e906817bb2d966c3cc25122f0dae0b9d44c6d7fe9c5c4ab36513aca8104f5b4bf8452a33ce612a5e
ssdeep: 3072:vC8TizMW0ckLEHWdjKgXt6mt1Bcz9oa4ONNxpS2gkv1o54EgcU9ElrwCDVsNtvcO:vmzMWZiEBE6wMGaLNNxDv1aKIkh53BDR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16A14AD43DB68CE20C4A01C7AA5EB52CD6E15B199CF62902A335CD7FC7A3647CD84A3D9
sha3_384: c4534afcc30d97fd4cbcfbbab6daa8c73e41d773dafc5538abb7950e97a1e2fd52885632297aa7ceba7efba3f5765ba7
ep_bytes: 1cef22a44cb696234967afb28b24c708
timestamp: 1976-11-05 00:00:00

Version Info:

CompanyName: Wayne J. Radburn
FileDescription: PE/COFF File Viewer
FileVersion: 0.9.9.0
InternalName: PEview
LegalCopyright: Copyright© 1997-2011 Wayne J. Radburn
OriginalFilename: PEview.exe
ProductName: PEview
ProductVersion: 0.9.9.0
Translation: 0x0409 0x04e4

Trojan:Win32/Barys.GMA!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.105113
CAT-QuickHealTrojan.Barys.S32058459
SkyhighBehavesLike.Win32.Trojan.cc
McAfeeTrojan-FVOQ!EC2B52A7A83F
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0001b3411 )
K7GWTrojan ( 00571f921 )
Cybereasonmalicious.7a83fb
BitDefenderThetaGen:NN.ZexaF.36802.l80@aS09i7l
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HHBK
APEXMalicious
CynetMalicious (score: 100)
AlibabaTrojan:Win32/Barys.5a60cb03
NANO-AntivirusTrojan.Win32.Kryptik.foobtk
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Kryptik.gify
F-SecureTrojan.TR/Crypt.XPACK.Gen
Trapminemalicious.high.ml.score
SophosMal/Inject-GJ
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
VaristW32/Dacic.E.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=88)
Antiy-AVLGrayWare/Win32.Kryptik.gifq
Kingsoftmalware.kb.a.1000
GridinsoftTrojan.Win32.Kryptik.sa
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Generic.D19A99
MicrosoftTrojan:Win32/Barys.GMA!MTB
GoogleDetected
AhnLab-V3Packed/Win.FJB.R621354
VBA32Trojan.Khalesi
ALYacTrojan.GenericKDZ.105113
TACHYONTrojan/W32.Selfmod
Cylanceunsafe
RisingTrojan.Kryptik!1.B34D (CLASSIC)
IkarusTrojan.Patched
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan:Win/Barys.GMA!MTB

How to remove Trojan:Win32/Barys.GMA!MTB?

Trojan:Win32/Barys.GMA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment