Trojan

How to remove “Trojan:Win32/Barys.GMA!MTB”?

Malware Removal

The Trojan:Win32/Barys.GMA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Barys.GMA!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Barys.GMA!MTB?


File Info:

name: 7BC32A0900DA4FCBA659.mlw
path: /opt/CAPEv2/storage/binaries/345b63988d453f83285be9c40aa926bea7fb784914e6c095ec5e9503ca9c9df9
crc32: 705E77A8
md5: 7bc32a0900da4fcba659bbe396143cd4
sha1: 48ff058c452335f21168d6f3135d2bbc7a0680c6
sha256: 345b63988d453f83285be9c40aa926bea7fb784914e6c095ec5e9503ca9c9df9
sha512: 11d02736c05bcb8707d4ad48fdc97c620923132e6a0303678f53dda461a415bd789c19aaa59374da00bdde1d5c0d0923a64a049202d8d22525e1c5dca9ec4791
ssdeep: 6144:DTorz7b3GJiPSNnKB6N39U4sZ20W7cyqCxSngmMBqfycuPbUl0i5cD5J:Iz7yoknQWgk0npM4dl0v5J
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11484D09A765C8E12C97E3637267972C575796A1F693D604C5CDC830B78B2C3B828F3A0
sha3_384: ddf2bfb109a73a2fe0f398ca99c9981646f59a3c62f596d0afb9ae60e645c8aad96c8f632257abfd7d27aad2664817e2
ep_bytes: c71a1dda9743a95d929290cc50d1f876
timestamp: 1971-05-16 00:00:00

Version Info:

CompanyName: Wayne J. Radburn
FileDescription: PE/COFF File Viewer
FileVersion: 0.9.9.0
InternalName: PEview
LegalCopyright: Copyright© 1997-2011 Wayne J. Radburn
OriginalFilename: PEview.exe
ProductName: PEview
ProductVersion: 0.9.9.0
Translation: 0x0409 0x04e4

Trojan:Win32/Barys.GMA!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Dacic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.Dacic.8952383F.A.360C0C76
SkyhighBehavesLike.Win32.Generic.fc
McAfeePacked-FJB!7BC32A0900DA
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.3766585
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0001b3411 )
AlibabaTrojan:Win32/Copak.5f559efb
K7GWTrojan ( 0001b3411 )
Cybereasonmalicious.c45233
ArcabitDeepScan:Generic.Dacic.8952383F.A.360C0C76
BitDefenderThetaGen:NN.ZexaF.36680.y43@aazQJtd
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HHBK
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Razy-9786051-0
KasperskyTrojan.Win32.Copak.aoetb
BitDefenderDeepScan:Generic.Dacic.8952383F.A.360C0C76
NANO-AntivirusTrojan.Win32.Kryptik.foobtk
AvastWin32:TrojanX-gen [Trj]
EmsisoftDeepScan:Generic.Dacic.8952383F.A.360C0C76 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebTrojan.Siggen22.64307
VIPREDeepScan:Generic.Dacic.8952383F.A.360C0C76
TrendMicroTROJ_GEN.R002C0DLD23
SophosMal/Inject-GJ
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
VaristW32/Dacic.E.gen!Eldorado
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=82)
Antiy-AVLGrayWare/Win32.Kryptik.gifq
Kingsoftmalware.kb.a.902
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Barys.GMA!MTB
ZoneAlarmTrojan.Win32.Copak.aoetb
GDataWin32.Trojan.PSE.109W4IM
GoogleDetected
Acronissuspicious
TACHYONTrojan/W32.Selfmod
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DLD23
TencentTrojan.Win32.Kryptik.gify
IkarusTrojan.Patched
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Barys.GMA!MTB?

Trojan:Win32/Barys.GMA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment