Malware

Barys.1100 (B) removal

Malware Removal

The Barys.1100 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.1100 (B) virus can do?

  • At least one process apparently crashed during execution
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid

How to determine Barys.1100 (B)?


File Info:

name: 8B0D0C59E4E634353C2E.mlw
path: /opt/CAPEv2/storage/binaries/181b6366ba2454ad485c6be28828e2434235b9b40004c6c6061ba3d26fbd2ec1
crc32: FDE5269C
md5: 8b0d0c59e4e634353c2e8d7d57c48ed0
sha1: 9704699aff7b803b0ca91415702e84e8472cb9e3
sha256: 181b6366ba2454ad485c6be28828e2434235b9b40004c6c6061ba3d26fbd2ec1
sha512: 4c0e1ed1df5baa49700427227d5ebf196e215cd4a4197d83e2a744564f3f360285dda119115a2c672f6519084a4521ae8aca53f82fac6f05939d459a25966c99
ssdeep: 6144:RhzIwPfPqw6E4RfzIpg2vKwPuLdXBGXzJU:Rhr/YorvNPuLdXBGDJU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E8440126B941C725F79987B15484EAD05A478D3D086CB40EFA7CBD3EA8722931E2734F
sha3_384: 1d008e623461671746f553cf271c7aca260ab3eb97ac2b8592e169c9c132b71658a8b12557c01ac022f8a1af984099e7
ep_bytes: 6a606818514000e881030000bf940000
timestamp: 2012-04-20 14:46:55

Version Info:

0: [No Data]

Barys.1100 (B) also known as:

LionicTrojan.Win32.Tipp.lBqC
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
FireEyeGeneric.mg.8b0d0c59e4e63435
ALYacGen:Variant.Barys.1100
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforSpyware.Win32.Zbot.8
K7AntiVirusTrojan ( 0055e3991 )
AlibabaTrojanSpy:Win32/Injector.a086c53e
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.9e4e63
BitDefenderThetaGen:NN.ZexaF.34212.qqZ@aG27Ixac
VirITTrojan.Win32.FakeGdF.DC
CyrenW32/CeeInject.AN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.AAQ
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Tipp-6
KasperskyTrojan.Win32.Tipp.ekp
BitDefenderGen:Variant.Barys.1100
NANO-AntivirusTrojan.Win32.MlwGen.rpxre
SUPERAntiSpywareTrojan.Agent/Gen-Spy
MicroWorld-eScanGen:Variant.Barys.1100
AvastWin32:Citadel [Trj]
TencentMalware.Win32.Gencirc.10c2c1cb
Ad-AwareGen:Variant.Barys.1100
EmsisoftGen:Variant.Barys.1100 (B)
ComodoTrojWare.Win32.TrojanDropper.Agent.RANS@4omxo3
DrWebTrojan.Packed.22462
ZillyaTrojan.Injector.Win32.93989
McAfee-GW-EditionBehavesLike.Win32.Ransomware.dc
SophosMal/Generic-R + Troj/Agent-VQC
IkarusTrojan.Win32.Tipp
GDataGen:Variant.Barys.1100
JiangminTrojan/Generic.aaftu
WebrootW32.Trojan.Gen
AviraTR/Rogue.KD.605789
Antiy-AVLTrojan/Generic.ASMalwS.226DA
KingsoftWin32.Troj.Tipp.e.(kcloud)
ViRobotTrojan.Win32.A.Tipp.268839
ZoneAlarmTrojan.Win32.Tipp.ekp
MicrosoftVirTool:Win32/Injector.AX
AhnLab-V3Trojan/Win32.Tipp.R24801
McAfeePWS-Zbot.gen.zc
MAXmalware (ai score=100)
VBA32Trojan.Tipp
RisingSpyware.Zbot!8.16B (C64:YzY0Og0lkGJQROK1)
YandexTrojan.GenAsa!7cQYg2RJ9tg
MaxSecureTrojan.Malware.3870006.susgen
FortinetW32/Crypt.AABB!tr
AVGWin32:Citadel [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Barys.1100 (B)?

Barys.1100 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment