Malware

Barys.2216 (file analysis)

Malware Removal

The Barys.2216 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.2216 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.up-king.com

How to determine Barys.2216?


File Info:

crc32: 73D01C42
md5: 4f5d07fc6614fd4979ff5c990a330dd7
name: 4F5D07FC6614FD4979FF5C990A330DD7.mlw
sha1: 06a30b32a8dc413ae97009ec49cbfb2ea1077a08
sha256: 5b68b2f8882269e67dd149c660038d835446ffeaae7ed35284f2acb8a5ef750d
sha512: ea23cded569aa40da3463b9d6098a391a49e101ff6b9bbfe0a59ccb2739113693826bd4b99cca9c90a1a6c3aa8dab970573fea8f576dc762958b7670581a6a82
ssdeep: 1536:+4epR81xxuZ+kcZW5F4rIHH7+k74sn7coEqvoWuA0VOf6wgdG:HqaY5FR7+MhIFTWuJOMdG
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: Opera Mini 8 Handler PC.Djezzy....55.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: Opera Mini 8 Handler PC.Djezzy....55.exe

Barys.2216 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.2216
FireEyeGeneric.mg.4f5d07fc6614fd49
ALYacGen:Variant.Barys.2216
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00567a071 )
BitDefenderGen:Variant.Barys.2216
K7GWTrojan ( 00567a071 )
Cybereasonmalicious.c6614f
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:RATX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Steamilik.edzhxs
AegisLabTrojan.Win32.Generic.4!c
RisingDropper.Agent!8.2F (CLOUD)
Ad-AwareGen:Variant.Barys.2216
EmsisoftGen:Variant.Barys.2216 (B)
ComodoTrojWare.MSIL.Noancooe.CDT@7jluau
F-SecureHeuristic.HEUR/AGEN.1124829
DrWebTrojan.MulDrop7.47478
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
SophosMal/Generic-R + Troj/Mdrop-HZL
IkarusTrojan.MSIL.Inject
AviraHEUR/AGEN.1124829
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftTrojanDownloader:MSIL/Lorozoad.A
ArcabitTrojan.Barys.D8A8
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Barys.2216
CynetMalicious (score: 85)
McAfeeBackDoor-NJRat.a
MAXmalware (ai score=84)
MalwarebytesTrojan.Dropper
PandaTrj/CI.A
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.DTP
TencentMsil.Trojan-downloader.Steamilik.Pfjx
YandexTrojan.DL.Steamilik!9nBNlOL5A5M
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetMSIL/Agent.CDT!tr
BitDefenderThetaGen:NN.ZemsilF.34804.lm0@amCD6On
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.316

How to remove Barys.2216?

Barys.2216 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment