Malware

Zusy.302799 removal tips

Malware Removal

The Zusy.302799 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware - Review 2020

GridinSoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend to use GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the TRIAL period.
6-day free trial available.

What Zusy.302799 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Zusy.302799?


File Info:

name: 3A4C09ED2D4F8450D57F.mlw
path: /opt/CAPEv2/storage/binaries/85c022166aad82c90e1d2aa95f29d602cb80bf52e75832925e1fb797c7c166c0
crc32: 7F9D0D2A
md5: 3a4c09ed2d4f8450d57fa0b8590356f7
sha1: d9964941df635dcdcc66324949befab99f8922f7
sha256: 85c022166aad82c90e1d2aa95f29d602cb80bf52e75832925e1fb797c7c166c0
sha512: 46ff5f0457e31cb72b5600b92c4e18516d0e5db92b7b15dc3558d2e772f5420571175a6a47a06db118c5eaf022aa2628eb34581084810a5aa633b995264da81c
ssdeep: 12288:UnXgvkQCWs2AtV44jE7TMTMxxWXwBJwBaYsGSM:UnXgvLsTP44DTukGJGa+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170D47C91E6C5C0B1FA2C18BC04E7D3BB67276B41A40BDA2343B8ED16792217E75E513B
sha3_384: 66c323b4f0d337b38596c0ac418d12164cf790db54037aa34b1b751a8cf58b651266cfa8fa5db251e2419f65bc6433ca
ep_bytes: 558bec6aff68a8384500688899430064
timestamp: 1970-01-01 02:24:15

Version Info:

Comments:
CompanyName:
FileDescription:
FileVersion: 1, 0, 9, 3017
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
PrivateBuild:
ProductName:
ProductVersion: 1, 0, 4, 423
SpecialBuild:
Translation: 0x0804 0x04b0

Zusy.302799 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.302799
FireEyeGeneric.mg.3a4c09ed2d4f8450
CAT-QuickHealTrojan.Halfy.AX4
ALYacGen:Variant.Zusy.302799
CylanceUnsafe
ZillyaTrojan.Halfy.Win32.1
Sangfor[ARMADILLO V1.71]
K7AntiVirusAdware ( 004c15e01 )
K7GWAdware ( 004c15e01 )
Cybereasonmalicious.d2d4f8
BitDefenderThetaGen:NN.ZexaF.34582.Lq1@aWVFqhob
VirITTrojan.Win32.Generic.AZYI
CyrenW32/S-7d09d051!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Adware.BHO.NLL
BaiduWin32.Trojan.Agent.aau
ClamAVWin.Malware.Jaik-9660700-0
KasperskyTrojan.Win32.Halfy.ax
BitDefenderGen:Variant.Zusy.302799
NANO-AntivirusTrojan.Win32.Halfy.dqjofo
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b171c0
Ad-AwareGen:Variant.Zusy.302799
EmsisoftGen:Variant.Zusy.302799 (B)
ComodoTrojWare.Win32.PSW.Agent.WTC@5j6zz0
DrWebTrojan.KillFiles.26726
VIPREGen:Variant.Zusy.302799
McAfee-GW-EditionTrojan-FEDO!3A4C09ED2D4F
Trapminemalicious.high.ml.score
SophosMal/Generic-S
APEXMalicious
GDataGen:Variant.Zusy.302799
JiangminTrojan/Halfy.a
AviraTR/Graftor.fragtz
Antiy-AVLTrojan/Generic.ASMalwS.3C54
ArcabitTrojan.Zusy.D49ECF
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.OnlineGameHack.R129856
McAfeeTrojan-FEDO!3A4C09ED2D4F
MAXmalware (ai score=88)
VBA32BScope.Trojan.KillFiles
MalwarebytesMalware.AI.3734768840
RisingTrojan.Generic@AI.92 (RDML:yeyqH4poC6MwBFEmnWbsOw)
YandexTrojan.GenAsa!gwCx0Jv1iQ4
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Trojan.FEDO!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen

How to remove Zusy.302799?

Zusy.302799 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment