Categories: Malware

About “Barys.112135” infection

The Barys.112135 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.112135 virus can do?

  • Executable code extraction
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Barys.112135?


File Info:

crc32: 68BBF8DEmd5: bc5366b4bdc98f1997b3dbda28611a5bname: BC5366B4BDC98F1997B3DBDA28611A5B.mlwsha1: c9cb3e8d4b994b9758b02fb5b0cabe401d6ee557sha256: 24c18cf443aaba1601ac00c24bd3ae9ca283f62e1ebaa3c77e0f6796d5b841d8sha512: b5b700b498af963127a1dc48af2b30f92f162dea66b6db87a30cf97fd46c18e5c57ebb91d75199aa1bd88e59d66130e1d42be2d8cb5d83014f4c288bc0ebb429ssdeep: 3072:CENzS6OXAeRr0RFqeR0nbeRlBWtTv6alKmQbEOVRm:CI4AVu/nbeBWtL6alziNatype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Barys.112135 also known as:

Bkav W32.AIDetect.malware2
K7AntiVirus Trojan ( 0040f7b81 )
Elastic malicious (high confidence)
DrWeb Trojan.VbCrypt.250
Cynet Malicious (score: 100)
ALYac Gen:Variant.Barys.112135
Cylance Unsafe
Zillya Worm.Ngrbot.Win32.6222
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (D)
K7GW Trojan ( 0040f7b81 )
Cybereason malicious.4bdc98
Cyren W32/Dorkbot.AM.gen!Eldorado
Symantec Trojan.Gen.X
ESET-NOD32 Win32/TrojanClicker.VB.NZZ
APEX Malicious
Avast Win32:GenMalicious-XN [Trj]
ClamAV Win.Worm.Ngrbot-7752131-0
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Gen:Variant.Barys.112135
NANO-Antivirus Trojan.Win32.Ngrbot.dergcd
MicroWorld-eScan Gen:Variant.Barys.112135
Tencent Win32.Worm.Ngrbot.Pgwh
Ad-Aware Gen:Variant.Barys.112135
Sophos Mal/Generic-S
Comodo Malware@#1j0afg16nif5n
BitDefenderTheta Gen:NN.ZevbaF.34266.jmX@aKN6cEk
VIPRE Trojan.Win32.Clicker!BT
TrendMicro TROJ_SPNR.38KG14
McAfee-GW-Edition BehavesLike.Win32.Generic.cc
FireEye Generic.mg.bc5366b4bdc98f19
Emsisoft Gen:Variant.Barys.112135 (B)
SentinelOne Static AI – Malicious PE
Jiangmin Worm/Ngrbot.bgu
Avira WORM/Ngrbot.rfdas
Antiy-AVL Worm/Win32.Ngrbot
Microsoft PWS:Win32/Zbot.GG!MTB
Arcabit Trojan.Barys.D1B607
SUPERAntiSpyware Trojan.Agent/Gen-Zusy
GData Gen:Variant.Barys.112135
TACHYON Trojan/W32.VB-Agent.161844
AhnLab-V3 Malware/Win32.Generic.C577899
Acronis suspicious
McAfee RDN/Sdbot.worm!cb
MAX malware (ai score=81)
VBA32 Worm.Ngrbot
Malwarebytes Trojan.LVBP
Panda Trj/Chgt.E
TrendMicro-HouseCall TROJ_SPNR.38KG14
Yandex Trojan.GenAsa!f5HjA96+itM
Ikarus Trojan-Clicker.Win32.Tolouge
Fortinet W32/Generic.AC.20789C!tr
AVG Win32:GenMalicious-XN [Trj]

How to remove Barys.112135?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Malware.AI.4222225806 malicious file

The Malware.AI.4222225806 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Malware.AI.1862100968 removal guide

The Malware.AI.1862100968 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Win32:VB-OLS [Trj] removal

The Win32:VB-OLS [Trj] is considered dangerous by lots of security experts. When this infection is…

2 hours ago

How to remove “Trojan:Win32/Smokeloader.CCDO!MTB”?

The Trojan:Win32/Smokeloader.CCDO!MTB is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Should I remove “TrojanDownloader:MSIL/RedLineStealer.KL!MTB”?

The TrojanDownloader:MSIL/RedLineStealer.KL!MTB is considered dangerous by lots of security experts. When this infection is active,…

3 hours ago

How to remove “Malware.AI.4139232050”?

The Malware.AI.4139232050 is considered dangerous by lots of security experts. When this infection is active,…

3 hours ago