Malware

Should I remove “Zusy.304350”?

Malware Removal

The Zusy.304350 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.304350 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • CAPE detected the mimikatz malware family
  • Creates a copy of itself
  • The sample wrote data to the system hosts file.
  • Modifies Image File Execution Options, indicative of process injection or persistence
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine Zusy.304350?


File Info:

name: A4BC88B6C6430D6B1F11.mlw
path: /opt/CAPEv2/storage/binaries/029565706451498774591f203e1152d940c6d5e0b6112a664728c4a3beb63d0b
crc32: 31E75248
md5: a4bc88b6c6430d6b1f11b44f3c095971
sha1: d81f4c2fd7a283f0c9d61f6ee524c2dd58ea46f6
sha256: 029565706451498774591f203e1152d940c6d5e0b6112a664728c4a3beb63d0b
sha512: 4e8834cd7014bf3549695f65f33fa90c536fa27260f5579ea6b4fe6a99dd9f2ee2173abe7019d63d37006c23d198c3c2f173d0554138ddefa98d8ec04c03667d
ssdeep: 98304:T/WXTBJYaVmknGzZr+H3O5SEPFtmOb9G1u5v/nZVnivsAl0kroSCa:KXTYimknGzwH3OgEPH39JX/nivPli
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17456E1315B435462C0C642F0C676DEEF38B770B845D8794E778A5AA19E78380A9BD32F
sha3_384: 7a0438df0a994323fe5f8705e48aa149b47c078b6a354159a5e12b9322803ecdb61546c02d986359bb0adcb2383bffca
ep_bytes: 558bec6aff6880ef450068646c440064
timestamp: 2019-07-21 20:45:59

Version Info:

0: [No Data]

Zusy.304350 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Hosts.46474
MicroWorld-eScanGen:Variant.Zusy.304350
FireEyeGeneric.mg.a4bc88b6c6430d6b
CAT-QuickHealTrojanpws.Qqpass.16543
McAfeeGenericRXAA-AA!A4BC88B6C643
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
Cybereasonmalicious.6c6430
BitDefenderThetaGen:NN.ZexaF.34638.@pZ@auRfAic
CyrenW32/BlackMoon.J.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
TrendMicro-HouseCallBackdoor.Win32.ZEGOST.SMS
ClamAVWin.Trojan.BlackMoon-7136668-0
KasperskyHEUR:Trojan.Win32.Blamon.vho
BitDefenderGen:Variant.Zusy.304350
AvastWin32:Malware-gen
TencentTrojan.Win32.Coinminer.16000308
Ad-AwareGen:Variant.Zusy.304350
EmsisoftGen:Variant.Zusy.304350 (B)
ZillyaTrojan.Blamon.Win32.879
TrendMicroBackdoor.Win32.ZEGOST.SMS
McAfee-GW-EditionBehavesLike.Win32.Exploita043.vc
SentinelOneStatic AI – Malicious PE
SophosGeneric ML PUA (PUA)
IkarusTrojan-PSW.QQpass
GDataWin32.Trojan.Agent.WP
AviraHEUR/AGEN.1227828
ArcabitTrojan.Zusy.D4A4DE
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Backdoor.R284823
VBA32BScope.Trojan.Miancha
MalwarebytesTrojan.Downloader
APEXMalicious
RisingTrojan.Kryptik!8.8 (TFE:dGZlOgXTxvUVZYco9Q)
YandexTrojan.GenAsa!/Z6D25o4ywM
MAXmalware (ai score=81)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.ESFJ!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Zusy.304350?

Zusy.304350 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment