Trojan

Should I remove “Trojan:Win32/Barys.GMA!MTB”?

Malware Removal

The Trojan:Win32/Barys.GMA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Barys.GMA!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Barys.GMA!MTB?


File Info:

name: 46970DE8E5DD2C76BDDE.mlw
path: /opt/CAPEv2/storage/binaries/1847271d95490537fa7130b945dd4d6e8cea2a691a3a22df14bd102a6eb6fde2
crc32: 9504BD78
md5: 46970de8e5dd2c76bdde2f3f824534d1
sha1: 40a78153a4a3739b24beee7ad602e2631444c6ce
sha256: 1847271d95490537fa7130b945dd4d6e8cea2a691a3a22df14bd102a6eb6fde2
sha512: 42da640865bca26b3865c734e1a5a7a6947844240c083e19f0080a753a59dff364c34012681378dcf6f07e3c8b6e6b66f7c969c7b07a78b88f9c5ccc125c41d8
ssdeep: 3072:AHZldRr+peQyz6SO6dAft1Klhoq/Q+Att3FqWPFMmtySLhCw3BDR:Ul7+pNfKlhoP33FFP2hSV53BDR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10914BFE1158FDB61CAA2833F4DAACB2583C0531A4DD9E0047CD0FE8DAF5B158A51B6BD
sha3_384: 8b318e31d24f61f9205b95acf41b8c5affc766eea45e502bd3a3ff6ec7b6747e7766fac9d4a7bc7b0c00db4b316cacfc
ep_bytes: de5943738e00f7f48bd1ce654992a6df
timestamp: 1976-11-05 00:00:00

Version Info:

CompanyName: Wayne J. Radburn
FileDescription: PE/COFF File Viewer
FileVersion: 0.9.9.0
InternalName: PEview
LegalCopyright: Copyright© 1997-2011 Wayne J. Radburn
OriginalFilename: PEview.exe
ProductName: PEview
ProductVersion: 0.9.9.0
Translation: 0x0409 0x04e4

Trojan:Win32/Barys.GMA!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanDeepScan:Generic.Dacic.8952383F.A.F5676A2B
SkyhighBehavesLike.Win32.MoonLight.cc
McAfeeTrojan-FVOQ!46970DE8E5DD
MalwarebytesGeneric.Malware.AI.DDS
VIPREDeepScan:Generic.Dacic.8952383F.A.F5676A2B
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0001b3411 )
K7GWTrojan ( 00571f921 )
Cybereasonmalicious.3a4a37
ArcabitDeepScan:Generic.Dacic.8952383F.A.F5676A2B
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HHBK
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Dridex-9861223-1
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderDeepScan:Generic.Dacic.8952383F.A.F5676A2B
NANO-AntivirusTrojan.Win32.Kryptik.foobtk
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Kryptik.gify
EmsisoftDeepScan:Generic.Dacic.8952383F.A.F5676A2B (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
SophosMal/Inject-GJ
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
VaristW32/Troj_Obfusc.G.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=85)
Antiy-AVLGrayWare/Win32.Kryptik.gifq
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Barys.GMA!MTB
ZoneAlarmVHO:Trojan.Win32.Copak.gen
GDataWin32.Trojan.PSE.1EYIFGG
GoogleDetected
AhnLab-V3Packed/Win.FJB.R621354
BitDefenderThetaGen:NN.ZexaF.36680.l80@aS09i7l
TACHYONTrojan/W32.Selfmod
VBA32Trojan.Khalesi
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
IkarusTrojan.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Barys.GMA!MTB?

Trojan:Win32/Barys.GMA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment