Malware

What is “Barys.132”?

Malware Removal

The Barys.132 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.132 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Spanish (Modern)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Barys.132?


File Info:

crc32: 2354E333
md5: 1f2d6f8a28e75ffc8dc6903e40abb5c7
name: 1F2D6F8A28E75FFC8DC6903E40ABB5C7.mlw
sha1: 8a7418103b5ba8bab83889be6f7fcc387abf0d28
sha256: 7806a13e1ca0ff607fb46f970b596c1f3490b1e456003cb3061967a7ff2701dc
sha512: 95e78dcc6f39e404f00de05a6aa58647b938aaac6ca2f826ec7e722031fd07f906ec59791beffef003f96906442ed0cf3d9c969f075a87a484c82cf9353f8e7d
ssdeep: 6144:V6pmkZGFeeYP2n+aC1meyUGimMOxrePlFqDHDypIVOBx:g0ksdwuW1meyUGphxrQP5x
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0c0a 0x04b0
LegalCopyright: Mister HQ. Corporationxa9 INC.xae 2010-08
InternalName: MisterHQ
FileVersion: 1.02.0015
CompanyName: Mister HQ Corporation
LegalTrademarks: Mister HQ. Corporationxa9 INC.xae 2010-08
Comments: Copyright xa9 2010-08 Mister HQ. Corporationxa9 INC.xae
ProductName: MisterHQ.exe
ProductVersion: 1.02.0015
FileDescription: Copyright xa9 2010-08 Mister HQ. Corporationxa9 INC.xae
OriginalFilename: MisterHQ.exe

Barys.132 also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.PWS.Banker.64355
CynetMalicious (score: 100)
ALYacGen:Variant.Barys.132
ZillyaTrojan.Banbra.Win32.10177
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Banker.1b80ee76
Cybereasonmalicious.a28e75
CyrenW32/VB.DO.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/VB.PMM
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Trojan-gen
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Barys.132
NANO-AntivirusTrojan.Win32.Banbra.kuctx
ViRobotTrojan.Win32.A.Banbra.273235
MicroWorld-eScanGen:Variant.Barys.132
TencentWin32.Trojan-banker.Banbra.Dzkn
Ad-AwareGen:Variant.Barys.132
SophosML/PE-A
ComodoMalware@#1t5djwpgze5l4
BitDefenderThetaGen:NN.ZevbaF.34050.qu0aaSaMTXO
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.VirRansom.dc
FireEyeGeneric.mg.1f2d6f8a28e75ffc
EmsisoftGen:Variant.Barys.132 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Banker.Banbra.ixf
AviraTR/Crypt.ASPM.Gen
eGambitGeneric.PSW
Antiy-AVLTrojan/Generic.ASMalwS.2D0F43
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Barys.132
AhnLab-V3Trojan/Win32.Banbra.C9795
McAfeeArtemis!1F2D6F8A28E7
MAXmalware (ai score=100)
PandaTrj/Banbra.GXN
YandexTrojan.PWS.Banbra!H4pIdHLyW4Q
IkarusTrojan-Banker.Win32.Banbra
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Banbra.AHYU!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.Hw8AEpsA

How to remove Barys.132?

Barys.132 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment