Malware

Barys.882 removal instruction

Malware Removal

The Barys.882 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.882 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Exhibits behavior characteristic of iSpy Keylogger
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

api.wipmania.com

How to determine Barys.882?


File Info:

crc32: 4DB92535
md5: 8bd2242f4e58e1f9e1cdf9162cd8e9a8
name: 8BD2242F4E58E1F9E1CDF9162CD8E9A8.mlw
sha1: 00de620aab33cdebc01f497071e8d3e33342e1a5
sha256: 5ed8bc3209bdbcd2d2835333008405971219598cefbef2b015911f902a83eb6f
sha512: 96da1699fe9ed4d09e299f9cfedb8af3c5226bb2356ea838b8688a3bdfa47fd200f46f8e7c87117dcbbe7268780ff428e469a85d263704b3fa3feab5946cf0f1
ssdeep: 6144:xZkAeUKK6RL1GNEqfipMUugP7r2Ir653fxKxjckqSWGF1Fe/WAGrbO/jnmkofuF:xaAqK2L1wEJMUugPuIrrx5qncs6rC/r
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: vps2.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: vps2.exe

Barys.882 also known as:

K7AntiVirusTrojan ( 00567a071 )
LionicTrojan.Win32.Generic.ly4v
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen1.6871
CynetMalicious (score: 100)
ALYacGen:Variant.Barys.882
CylanceUnsafe
ZillyaTrojan.Injector.Win32.617325
SangforTrojan.Win32.MSIL.Gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Injector.dc15d2e3
K7GWTrojan ( 00567a071 )
Cybereasonmalicious.f4e58e
CyrenW32/S-b748adc5!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.WN
APEXMalicious
AvastMSIL:Crypt-HB [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.882
NANO-AntivirusTrojan.Win32.Barys.fhqmcl
ViRobotTrojan.Win32.Z.Injector.376832.NQ
MicroWorld-eScanGen:Variant.Barys.882
TencentWin32.Trojan.Generic.Eeri
Ad-AwareGen:Variant.Barys.882
SophosMal/Generic-S
ComodoMalware@#1p3ga3fstdnc7
BitDefenderThetaGen:NN.ZemsilF.34236.xm0@aWO16Cm
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PK121
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGeneric.mg.8bd2242f4e58e1f9
EmsisoftGen:Variant.Barys.882 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Jorik.awuc
AviraTR/Dropper.MSIL.Gen
Antiy-AVLTrojan/Generic.ASMalwS.291DFBB
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Barys.882
Acronissuspicious
McAfeeGenericRXKE-BQ!8BD2242F4E58
VBA32TScope.Trojan.MSIL
PandaGeneric Malware
IkarusVirus.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.BDPW!tr
AVGMSIL:Crypt-HB [Trj]
Paloaltogeneric.ml

How to remove Barys.882?

Barys.882 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment