Malware

About “Zusy.293327” infection

Malware Removal

The Zusy.293327 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.293327 virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.293327?


File Info:

name: 068C30CD8350CEEFC86F.mlw
path: /opt/CAPEv2/storage/binaries/114f587365d07f62382b8ae6a37b7e67c65429bb7a10cc7fb62bbe85b5256daf
crc32: 478968E5
md5: 068c30cd8350ceefc86fb939b64e0ea5
sha1: 4eac6b7700bcaeddd7390b8d58205ead27da2a24
sha256: 114f587365d07f62382b8ae6a37b7e67c65429bb7a10cc7fb62bbe85b5256daf
sha512: 1acd5a250f20e0f8a4d903a774a990a91ea2aa33b7d635eb3e1178651dc64c355699d85caeda8d041ee88727ac35aa8aebbdd9cb19414b6978a1688472f28b5f
ssdeep: 24576:Nd5+j7o3mwNi5ARgIWhGzJ1Pyp6s7XzBLqpUGnmjyMfvkj:NnMnwNi5ARgIV1Pyt70Sjyave
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EA451264A484C2F6D94D10301A55CBE76D7E7D3267278EC332E83AAD7E712C1A632727
sha3_384: d9c6ca8aa9f155dfd3c38c2e6f6f2a91a58feed21752a6d5dbd7dc3e9cffc7f941c06938d3801cd3d3fbb87448809d56
ep_bytes: e80c360000e989feffff3b0de4435100
timestamp: 2010-09-06 10:20:55

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Office Word
FileVersion: 12.0.4518.1014
InternalName: WinWord
LegalCopyright: © 2006 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: WinWord.exe
ProductName: 2007 Microsoft Office system
ProductVersion: 12.0.4518.1014
Translation: 0x0000 0x04e4

Zusy.293327 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.293327
ClamAVWin.Malware.Ulise-9768992-0
FireEyeGeneric.mg.068c30cd8350ceef
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeGenericRXDF-ES!068C30CD8350
Cylanceunsafe
ZillyaDropper.Agent.Win32.379198
SangforTrojan.Win32.Save.a
Cybereasonmalicious.d8350c
BitDefenderThetaAI:Packer.65D5BED81F
CyrenW32/Occamy.I.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDropper.Agent.RJF
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.Win32.Generic
BitDefenderGen:Variant.Zusy.293327
NANO-AntivirusTrojan.Win32.Zusy.hvrtbw
SUPERAntiSpywareTrojan.Agent/Gen-Zusy
AvastWin32:DropperX-gen [Drp]
TencentMalware.Win32.Gencirc.10bb6b31
TACHYONTrojan/W32.Agent.1189376.T
EmsisoftGen:Variant.Zusy.293327 (B)
F-SecureHeuristic.HEUR/AGEN.1313003
DrWebTrojan.MulDrop6.18204
VIPREGen:Variant.Zusy.293327
TrendMicroTrojan.Win32.SALGOREA.SMLV
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
SophosTroj/Agent-BFWM
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.RD62IG
JiangminTrojan.Agentb.fds
AviraHEUR/AGEN.1313003
Antiy-AVLTrojan/Win32.AGeneric
XcitiumTrojWare.Win32.Salgorea.RPR@7tcxjx
ArcabitTrojan.Zusy.D479CF
ZoneAlarmHEUR:Backdoor.Win32.Generic
MicrosoftTrojan:Win32/Salgorea.C!dha
GoogleDetected
AhnLab-V3Trojan/Win.Salgorea.R597030
Acronissuspicious
VBA32Trojan.Agentb
ALYacGen:Variant.Zusy.293327
MAXmalware (ai score=83)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojan.Win32.SALGOREA.SMLV
RisingTrojan.Agent!1.B332 (CLASSIC)
YandexTrojan.GenAsa!VZtBpaHf7NI
IkarusTrojan-Dropper.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.RJF!tr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Zusy.293327?

Zusy.293327 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment