Trojan

Trojan:Win32/Barys.GMA!MTB (file analysis)

Malware Removal

The Trojan:Win32/Barys.GMA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Barys.GMA!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Barys.GMA!MTB?


File Info:

name: 7718B83F58C9154C4096.mlw
path: /opt/CAPEv2/storage/binaries/b958e7a9b1181411a3cfde7e46d5f1595a6918f0cdaec37a69f4e8d49adc1c85
crc32: C961F087
md5: 7718b83f58c9154c4096c7b2feda05da
sha1: 3adc794572637121575e3bbae83a72d5da818de1
sha256: b958e7a9b1181411a3cfde7e46d5f1595a6918f0cdaec37a69f4e8d49adc1c85
sha512: 917bdbef4b908e45ee3fafc4432b7796fbe9849ebfb4433ff6aa70da675667174e24a8188a21c95020437b93a1962f4fb52c118b2acabf105bcc71f50c82472d
ssdeep: 3072:O+r96OvAaMtwrQi+g0E5it1LHXfoZL2R4DoqRj6oKBsfa2x+zvhCw3BDR:B56OILwrCuSLHXfEL2R4DTj6KZ+z553f
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15F14BFA115894E58DCE035730E36EA62A200FDDC5253C6ADF4D453EB0BFAEAD09B9F11
sha3_384: cec559edea73e05d83bc424d01d6b8f9c798f0378e602bd029e33b2881a64169ce45ca2501b3f7f28fddc364b6d472c1
ep_bytes: 0dc9e3a55d90572258416eb39a020609
timestamp: 1976-11-05 00:00:00

Version Info:

CompanyName: Wayne J. Radburn
FileDescription: PE/COFF File Viewer
FileVersion: 0.9.9.0
InternalName: PEview
LegalCopyright: Copyright© 1997-2011 Wayne J. Radburn
OriginalFilename: PEview.exe
ProductName: PEview
ProductVersion: 0.9.9.0
Translation: 0x0409 0x04e4

Trojan:Win32/Barys.GMA!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.432776
SkyhighBehavesLike.Win32.MoonLight.cc
McAfeeTrojan-FVOQ!7718B83F58C9
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Lazy.432776
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0001b3411 )
K7GWTrojan ( 00571f921 )
Cybereasonmalicious.572637
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik_AGen.BGV
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Dridex-9861223-1
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderGen:Variant.Lazy.432776
NANO-AntivirusTrojan.Win32.Kryptik.foobtk
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Kryptik.gifyb
TACHYONTrojan/W32.Selfmod
EmsisoftGen:Variant.Lazy.432776 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
SophosMal/Inject-GJ
IkarusTrojan.Patched
GDataWin32.Trojan.PSE.1EYIFGG
WebrootW32.Trojan.Gen
VaristW32/Dacic.E.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
Antiy-AVLGrayWare/Win32.Kryptik.gifq
Kingsoftmalware.kb.a.997
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Lazy.D69A88
ZoneAlarmVHO:Trojan.Win32.Copak.gen
MicrosoftTrojan:Win32/Barys.GMA!MTB
GoogleDetected
AhnLab-V3Packed/Win.FJB.R621354
BitDefenderThetaGen:NN.ZexaF.36680.l80@aS09i7l
MAXmalware (ai score=85)
VBA32Trojan.Khalesi
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Barys.GMA!MTB?

Trojan:Win32/Barys.GMA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment