Malware

Zusy.302069 (B) removal instruction

Malware Removal

The Zusy.302069 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.302069 (B) virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid

How to determine Zusy.302069 (B)?


File Info:

name: 7325ABEB4E2FBE383475.mlw
path: /opt/CAPEv2/storage/binaries/eac5d33dae34210e3693f002b3f4412756152b33f549484b99cab677fbdd4fa7
crc32: E885C092
md5: 7325abeb4e2fbe3834756b2e9e2cd371
sha1: 1b5d276d79f486bd38d6446852c5d42f26dd71a8
sha256: eac5d33dae34210e3693f002b3f4412756152b33f549484b99cab677fbdd4fa7
sha512: 59af819f9478204dbabaac3c133703b14777a24c094d2f916f226c0778b00b349e85ae34035b5d0d65dd59f8ff192b6008d0dddd68f42e8f02a62b175bf45614
ssdeep: 1536:1q1utPdWHdPEzoT2/VhWbnoZSKLfiGGPgq3ePAH8PNqT3T6rR/x9s:1fPdWqV0CvL6GGCPNqTj6rR/x9s
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17934F5117640C471F3590B324916EAE04969AC3D1AE4E88FF7B87E3A5D322C39A7725F
sha3_384: 508efbdf7c4456a3401672bda7e212f15276ef794df0c3aea5b64119fe927e1ea788ba3b4e6b850dc263d1541121e8cf
ep_bytes: 8bc583c40c8d50028d642400668b0883
timestamp: 2015-08-18 06:52:56

Version Info:

0: [No Data]

Zusy.302069 (B) also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Urelas.4!c
MicroWorld-eScanGen:Variant.Zusy.302069
CAT-QuickHealTrojan.Beaugrit.14262
SkyhighBehavesLike.Win32.Generic.dt
ALYacGen:Variant.Zusy.302069
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.ShadowBrokersC
K7AntiVirusTrojan ( 0052964f1 )
BitDefenderGen:Variant.Zusy.302069
K7GWTrojan ( 0052964f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36792.oqY@auYkZhl
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Dropper.Tinba-9943147-2
RisingTrojan.Urelas!1.BE13 (CLASSIC)
TACHYONTrojan/W32.Agent.233472.AWO
SophosML/PE-A
BaiduWin32.Trojan.Urelas.b
F-SecureTrojan.TR/Patched.Ren.Gen
VIPREGen:Variant.Zusy.302069
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7325abeb4e2fbe38
EmsisoftGen:Variant.Zusy.302069 (B)
IkarusTrojan.Dropper
VaristW32/Urelas.AP.gen!Eldorado
AviraTR/Patched.Ren.Gen
Antiy-AVLVirus/Win32.Expiro.imp
Kingsoftmalware.kb.b.999
MicrosoftTrojan:Win32/Urelas.AA
XcitiumTrojWare.Win32.Urelas.AB@56xqzc
ArcabitTrojan.Zusy.D49BF5
GDataWin32.Trojan.PSE.122A5Z1
GoogleDetected
Acronissuspicious
McAfeeGenericRXAA-FA!7325ABEB4E2F
MAXmalware (ai score=83)
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BH0CK823
TencentTrojan.Win32.Urelas.16000161
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.49CA!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.d79f48
AvastWin32:Evo-gen [Trj]

How to remove Zusy.302069 (B)?

Zusy.302069 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment