Malware

Barys.884 (B) (file analysis)

Malware Removal

The Barys.884 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.884 (B) virus can do?

  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Barys.884 (B)?


File Info:

name: 3DDF3C605C8100295FC2.mlw
path: /opt/CAPEv2/storage/binaries/0db69bd4fa187c32a72da74a1d3c79eba269ca7c6d8e78e1230a03458340178d
crc32: 1A3E4DFB
md5: 3ddf3c605c8100295fc290d4f74ebe40
sha1: be54a42e3745a74b11e5416ca97cc4a48ad9310f
sha256: 0db69bd4fa187c32a72da74a1d3c79eba269ca7c6d8e78e1230a03458340178d
sha512: f5e0062bff95a548ed61c784412810d42a6c6c713a048104791e26042771d69d3dd15da2a0bfdd18c6a90e0830b44de939121cfcdba603deab2989be7b304383
ssdeep: 98304:lmQXcJz3TILexiAVewOICqXXeo5MEiFpSz3uOr7+OdCbDYv:lmN3DitqX2z8dr7+OEbD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T182260074338FCC9A8E06276377414E0FA578585996DCD8CBADA52D783E05E9B7CBE200
sha3_384: f7e7427362d063fb6ce7f9905d2f127f9187cc69b8d5bc161fc538a106bebb344afb80ef0bceb201bc4a1a99f41a4019
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-12-02 13:48:49

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: Program.exe
LegalCopyright:
OriginalFilename: Program.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Barys.884 (B) also known as:

LionicTrojan.MSIL.Bitser.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.884
FireEyeGeneric.mg.3ddf3c605c810029
ALYacGen:Variant.Barys.884
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.05c810
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/GenKryptik.EUPB
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Downloader.MSIL.Bitser.gen
BitDefenderGen:Variant.Barys.884
AvastWin32:RATX-gen [Trj]
TencentMsil.Trojan.Genkryptik.Losl
Ad-AwareGen:Variant.Barys.884
SophosMal/Generic-S
DrWebTrojan.Siggen10.39380
TrendMicroTROJ_GEN.R002C0WL321
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
EmsisoftGen:Variant.Barys.884 (B)
IkarusTrojan.MSIL.Krypt
GDataGen:Variant.Barys.884
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34E1C74
ArcabitTrojan.Barys.884
ViRobotTrojan.Win32.Z.Barys.4636160
MicrosoftBackdoor:Win32/Bladabindi!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Generic.C4279859
McAfeeArtemis!3DDF3C605C81
MAXmalware (ai score=86)
MalwarebytesBackdoor.Bladabindi.MSIL
TrendMicro-HouseCallTROJ_GEN.R002C0WL321
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/GenKryptik.EUPB!tr
BitDefenderThetaGen:NN.ZemsilF.34062.@p0@aGUCtSh
AVGWin32:RATX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Barys.884 (B)?

Barys.884 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment