Malware

Barys.2980 removal guide

Malware Removal

The Barys.2980 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.2980 virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Barys.2980?


File Info:

name: A7DC8A6CBB4313CE023D.mlw
path: /opt/CAPEv2/storage/binaries/0c82a9e38fc2e6d99c46eac69f7a1a46104e34f576cba075626a0dd689c3b041
crc32: 8967DAA4
md5: a7dc8a6cbb4313ce023d9bc5cefd5469
sha1: a07285a6aa04d3c8fe2c802558ee9d083c437eef
sha256: 0c82a9e38fc2e6d99c46eac69f7a1a46104e34f576cba075626a0dd689c3b041
sha512: 5aa3d299846a1ce31a0e42df06aa2b86d5d5edbbfdbc0b78e85a34845f816092005964cb92c9d3d7f9b3e29bf8367e194f00a93a49ade05a33a92a38402f5d5d
ssdeep: 49152:oWEJTw00I+83KMY2Bkrqx+rUcmbxjABhSaC:
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D395FB3439FE501AB173FF652EE8B9EAD9DEFB333606542D109203474622A41EE9253D
sha3_384: 696f1009a85293180abbdc6df58ebd707ec142fa205ecdd0277e87cb4c6a8e4513b643a532796fb56046ea03d93e6b55
ep_bytes: ff250020400000000000000000000000
timestamp: 2010-11-16 00:45:20

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: Nexus Radio.exe
LegalCopyright:
OriginalFilename: Nexus Radio.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Barys.2980 also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Generic.lj8t
Elasticmalicious (high confidence)
FireEyeGeneric.mg.a7dc8a6cbb4313ce
SkyhighBehavesLike.Win32.Dropper.tz
McAfeeArtemis!A7DC8A6CBB43
Cylanceunsafe
VIPREGen:Variant.Barys.2980
SangforSuspicious.Win32.Save.a
AlibabaTrojan:MSIL/Injector.dab057f6
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.CKF
APEXMalicious
ClamAVWin.Dropper.Barys-9873594-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.2980
NANO-AntivirusTrojan.Win32.TrjGen.itfoe
MicroWorld-eScanGen:Variant.Barys.2980
AvastWin32:RATX-gen [Trj]
TencentWin32.Trojan.Generic.Bdhl
SophosMal/MSIL-BN
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.InjectNET.14
ZillyaTrojan.Genome.Win32.109369
EmsisoftGen:Variant.Barys.2980 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.2980
JiangminTrojan/Genome.brtz
WebrootW32.InfoStealerFignotok.A
VaristW32/Risk.ZFBO-5530
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Trojan.Generic.a
XcitiumMalware@#2aphbtevdwn6o
ArcabitTrojan.Barys.DBA4
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Fignotok.A
GoogleDetected
ALYacGen:Variant.Barys.2980
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaGeneric Malware
RisingMalware.Obfus/MSIL@AI.81 (RDM.MSIL2:jnsFoDuTAfWiiPmb7vD7QA)
IkarusVirus.Win32.BeeInject
FortinetMSIL/Injector.PE!tr
BitDefenderThetaAI:Packer.529BD58D20
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.6aa04d
DeepInstinctMALICIOUS

How to remove Barys.2980?

Barys.2980 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment