Malware

Win32:Susn-AQ [Trj] removal guide

Malware Removal

The Win32:Susn-AQ [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Susn-AQ [Trj] virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics

How to determine Win32:Susn-AQ [Trj]?


File Info:

name: BD20F1DE3638E5A55A34.mlw
path: /opt/CAPEv2/storage/binaries/ee2dc3a7d837139c189cc22f6a2221ebafd0c816d2500fc2d0ec507cfec46515
crc32: DFB34119
md5: bd20f1de3638e5a55a3482140e62c0c6
sha1: e422c6496a67e43d3394416da1afde2229940572
sha256: ee2dc3a7d837139c189cc22f6a2221ebafd0c816d2500fc2d0ec507cfec46515
sha512: 1096a95fc1b62d7ef12ee05374ce0346dee20cb5bd28fc01202226d84f597c899af5c41985be6de9d6bce0162c1e1e8a6c66855bba77773d83abb845222aecae
ssdeep: 6144:wNUwFtrVmr4hL/cVyybGId2zcqPALwogJz/ZIkxiv+:eJbs+rkyyH4wqT/mkxQ+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A7441236B9D37DE7CB48553AA132C41B331C3764DA1A5CE1B130AAA111FED09AE28FD5
sha3_384: 5c0d6a701095310e0840b1778a83cace06b53dee3776f4348d86a6333b85cd5f37d1c7428552c80efde33d9741a07c60
ep_bytes: 60be006043008dbe00b0fcffc7879c90
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32:Susn-AQ [Trj] also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.bd20f1de3638e5a5
CAT-QuickHealTrojanPWS.Zbot.Gen
ALYacTrojan.Generic.7694176
CylanceUnsafe
VIPREVirTool.Win32.CeeInject.gen.iha (v)
SangforTrojan.Win32.AGEN.1005337
K7AntiVirusRiskware ( 0015e4f11 )
AlibabaVirTool:Win32/Obfuscator.aff3c7ab
K7GWRiskware ( 0015e4f11 )
Cybereasonmalicious.e3638e
VirITTrojan.Win32.Generic.JIS
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Generic.7694176
NANO-AntivirusTrojan.Win32.Panda.bbmdac
MicroWorld-eScanTrojan.Generic.7694176
AvastWin32:Susn-AQ [Trj]
TencentWin32.Trojan.Generic.Pgcm
Ad-AwareTrojan.Generic.7694176
SophosMal/Generic-R + Mal/EncPk-AFT
ComodoTrojWare.Win32.Injector.UTQ@4qkx9r
DrWebTrojan.PWS.Panda.2401
ZillyaTrojan.Jorik.Win32.116761
TrendMicroTROJ_OBFUSCATOR_FE1800B1.UVPM
McAfee-GW-EditionBehavesLike.Win32.ZBot.dc
EmsisoftTrojan.Generic.7694176 (B)
IkarusWin32.Karagany
GDataTrojan.Generic.7694176
JiangminTrojan/Jorik.ekim
AviraHEUR/AGEN.1233058
Antiy-AVLTrojan/Generic.ASMalwS.184181B
KingsoftWin32.Troj.Zbot.go.(kcloud)
ViRobotTrojan.Win32.A.Zbot.273408.O[UPX]
ZoneAlarmTrojan.Win32.Agent.gen
MicrosoftTrojan:Win32/Ditertag.A
AhnLab-V3Trojan/Win32.Jorik.R28518
McAfeeArtemis!BD20F1DE3638
VBA32TScope.Trojan.Delf
TrendMicro-HouseCallTROJ_OBFUSCATOR_FE1800B1.UVPM
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.GenAsa!UdvClXpYzpA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Zbot.AJY!tr.pws
BitDefenderThetaAI:Packer.B0A5537F21
AVGWin32:Susn-AQ [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Win32:Susn-AQ [Trj]?

Win32:Susn-AQ [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment