Malware

Zusy.303214 information

Malware Removal

The Zusy.303214 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.303214 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Zusy.303214?


File Info:

name: 1C282BEF5EB2975551DC.mlw
path: /opt/CAPEv2/storage/binaries/18a5109f10f310c8da79354a9662779b6754d86fc43bfefbc6e626df2bd46a21
crc32: C93492DB
md5: 1c282bef5eb2975551dc5ea7e08de25a
sha1: 0b99293732ee09c7aa4c21e168d1cbb46926cf62
sha256: 18a5109f10f310c8da79354a9662779b6754d86fc43bfefbc6e626df2bd46a21
sha512: 5faadbdf08ea345bcf15d95baed08a5967420e510aef259a881519060f6b43d83085e38599173796205043a1bc3ffdd502fb847de55afa3adf3a66f436839e39
ssdeep: 49152:b7wRIZjco9JTZaqdwk0c05HGi03XyG+PjgmdUPQCrng3mD45S:vGIZjco9JYqdwkLcHH5G+0mdsQQnImDZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T146D50241B68380FAEB1F09704DB3A73599357E8A4E259FC397A4DDAD2D37980D13B212
sha3_384: 813cd0ab7a7b9f1872e81257f3b21afb5ef31eb9643766f960c47c5a6f77255c6aea1c7e3d3a5cffe7714179b1d4080c
ep_bytes: 558bec6aff6878cf6500682496460064
timestamp: 2014-04-03 06:57:12

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Zusy.303214 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Multi.Generic.mpTZ
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.303214
ClamAVWin.Malware.Generic-9820446-0
FireEyeGeneric.mg.1c282bef5eb29755
CAT-QuickHealHacktool.Flystudio.16558
ALYacGen:Variant.Zusy.303214
MalwarebytesPUP.Optional.ChinAd
CrowdStrikewin/malicious_confidence_60% (D)
K7GWAdware ( 004b87ea1 )
K7AntiVirusTrojan ( 005246d51 )
BitDefenderThetaGen:NN.ZexaF.34682.2s3@aW8PLJlb
CyrenW32/Trojan.GRW.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Zusy.303214
NANO-AntivirusTrojan.Win32.Graftor.fbifwl
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Zusy.303214
SophosGeneric PUA AL (PUA)
ComodoWorm.Win32.Dropper.RA@1qraug
VIPREGen:Variant.Zusy.303214
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
Trapminesuspicious.low.ml.score
EmsisoftApplication.Generic (A)
SentinelOneStatic AI – Malicious PE
Antiy-AVLTrojan/Generic.ASCommon.FA
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Application.PSE.1DNV50E
GoogleDetected
AhnLab-V3Malware/Win.Generic.C5112514
McAfeeGenericRXAA-AA!1C282BEF5EB2
MAXmalware (ai score=88)
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.65CA!tr
AVGWin32:Malware-gen
Cybereasonmalicious.f5eb29

How to remove Zusy.303214?

Zusy.303214 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment