Malware

Zusy.303446 (file analysis)

Malware Removal

The Zusy.303446 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.303446 virus can do?

  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Zusy.303446?


File Info:

crc32: AE10665D
md5: ca54990462409eb98cec9511515f9000
name: na02121.exe
sha1: 3004a1c0467d38587c567764e60d4637cab2b969
sha256: c2d009cb77eac521bc0aeb475d651648302854a7f80aa8b43475fec52a009078
sha512: 4d99a446d21de3c7d1133269e8a090f8b6cef9a8130a8d151b6235523d130950de2f3feba3901e568e4fe32c9f0d08a9d23a0cefb5bd8f93f12886e61aaa5811
ssdeep: 49152:yjVMYX4D9FhTv9Fvd3dv9CWAQMjcY50S8/l86kJTPkGqH5zHPTT+24tXFNJFZmA:yjVdIDxDbvOrJTPkGFN5mA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.303446 also known as:

MicroWorld-eScanGen:Variant.Zusy.303446
FireEyeGeneric.mg.ca54990462409eb9
ALYacGen:Variant.Zusy.303446
CylanceUnsafe
ZillyaTrojan.Generic.Win32.1054550
BitDefenderGen:Variant.Zusy.303446
Cybereasonmalicious.462409
TrendMicroTROJ_GEN.R002C0PEL20
BitDefenderThetaGen:NN.ZelphiF.34122.@JW@a0UHOTiQ
CyrenW32/Trojan.LTSB-7534
AvastWin32:Malware-gen
GDataGen:Variant.Zusy.303446
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Generic.fd3d3a3b
AegisLabTrojan.Win32.Generic.4!c
RisingTrojan.Generic!8.C3 (CLOUD)
Ad-AwareGen:Variant.Zusy.303446
SophosMal/Generic-S
F-SecureTrojan.TR/Hijacker.Gen
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
EmsisoftGen:Variant.Zusy.303446 (B)
IkarusWin32.Outbreak
JiangminTrojan.Generic.eygjd
WebrootW32.Trojan.GenKD
AviraTR/Hijacker.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.BTSGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.Zusy.D4A156
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Occamy.AA
AhnLab-V3Trojan/Win32.Agent.R337593
Acronissuspicious
McAfeeArtemis!CA5499046240
VBA32Trojan.Wacatac
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PEL20
SentinelOneDFI – Malicious PE
FortinetW32/Ulise.1063!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Zusy.303446?

Zusy.303446 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment