Trojan

Trojan:Win32/Barys.GMA!MTB removal guide

Malware Removal

The Trojan:Win32/Barys.GMA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Barys.GMA!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Barys.GMA!MTB?


File Info:

name: B3C48F3DE1231303D285.mlw
path: /opt/CAPEv2/storage/binaries/95bb5e9750a9b4579affee4ddf8ecb0bea8d4872707fe82f0e387eda7ec63f62
crc32: 988B8086
md5: b3c48f3de1231303d2858d6a7c6f37c9
sha1: ca65587a5a08b588392f7273d1f30a4ad5ea1fe1
sha256: 95bb5e9750a9b4579affee4ddf8ecb0bea8d4872707fe82f0e387eda7ec63f62
sha512: 4b6e9543b599a5160ded2f2314f5975b6a44120a456528fb7ece22ee39e3a1b25f2a4f538a44834375df326c4c4cee4a15ac7899cabaad88a41daee4a83ea0ff
ssdeep: 24576:q3bTpezwMh6XFRbf0ezEM4dmv5BJtOtEM4dmv58:N8Wo7bf0ezj425zUtj4258
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T162F4D08E324CDD61CD352B7F1B69B20AA882992EEDBD607E55D8C70E4752DF3808F650
sha3_384: a91877223340ed7096473c1119dd3403d998971a7c0e46d0c9f6cc1d7d2c60f03880c0f502f08167fc3ded1083fcb400
ep_bytes: 414ea10d1117158a14c62c1bd68544a1
timestamp: 1971-05-16 00:00:00

Version Info:

CompanyName: Wayne J. Radburn
FileDescription: PE/COFF File Viewer
FileVersion: 0.9.9.0
InternalName: PEview
LegalCopyright: Copyright© 1997-2011 Wayne J. Radburn
OriginalFilename: PEview.exe
ProductName: PEview
ProductVersion: 0.9.9.0
Translation: 0x0409 0x04e4

Trojan:Win32/Barys.GMA!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Dacic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.Dacic.8952383F.A.8A6E8073
FireEyeGeneric.mg.b3c48f3de1231303
SkyhighBehavesLike.Win32.RAHack.bc
McAfeeTrojan-FVOQ!B3C48F3DE123
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.3766585
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0001b3411 )
K7AntiVirusTrojan ( 0001b3411 )
ArcabitDeepScan:Generic.Dacic.8952383F.A.8A6E8073
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HHBK
APEXMalicious
ClamAVWin.Packed.Razy-9786051-0
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderDeepScan:Generic.Dacic.8952383F.A.8A6E8073
NANO-AntivirusTrojan.Win32.Kryptik.foobtk
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Kryptik.gify
TACHYONTrojan/W32.Selfmod
EmsisoftDeepScan:Generic.Dacic.8952383F.A.8A6E8073 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebTrojan.PackedENT.139
VIPREDeepScan:Generic.Dacic.8952383F.A.8A6E8073
Trapminesuspicious.low.ml.score
SophosMal/Inject-GJ
IkarusTrojan.Patched
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Patched.Ren.Gen
VaristW32/Dacic.E.gen!Eldorado
Antiy-AVLGrayWare/Win32.Kryptik.gifq
Kingsoftmalware.kb.a.975
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Barys.GMA!MTB
ZoneAlarmVHO:Trojan.Win32.Copak.gen
GDataWin32.Trojan.PSE.109W4IM
CynetMalicious (score: 100)
Acronissuspicious
VBA32Trojan.Khalesi
ALYacDeepScan:Generic.Dacic.8952383F.A.8A6E8073
MAXmalware (ai score=84)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
YandexTrojan.Agent!RRuFJhSd6qY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.GIFQ!tr
BitDefenderThetaGen:NN.ZexaF.36802.W83@aSUsTC
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.de1231
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Barys.GMA!MTB

How to remove Trojan:Win32/Barys.GMA!MTB?

Trojan:Win32/Barys.GMA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment