Malware

Zusy.305076 (file analysis)

Malware Removal

The Zusy.305076 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.305076 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Zusy.305076?


File Info:

name: A1DB06964DDB2AA0B3C8.mlw
path: /opt/CAPEv2/storage/binaries/3cd68722b4c5b8bae39e306fd50966f7acebf7a812669132b5fe9962ce9e24f2
crc32: DB7CB52E
md5: a1db06964ddb2aa0b3c8ae0914e1c706
sha1: 8b7789f646f962803bcf324d88ec7952fd0d10da
sha256: 3cd68722b4c5b8bae39e306fd50966f7acebf7a812669132b5fe9962ce9e24f2
sha512: f8971bd7ad40dd94c579d2196e4a129b90102f8660b5aa0f53f6fe767a885ac02ad4ff579d33a5767f4edde074ced5d57e412a02cd19adcd87cf76e431c526da
ssdeep: 24576:uf1fzzSfHf2fVKf4IfsLf8OfvLGfCY8KqpLunbi1tCaINhYzmYT:Cz9FIOL8DROLunUqNhYzmY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T118759D3112F98116E1F6A634DD7A2EEE367A3D219F70C8EF619578EC04329D1A931B13
sha3_384: dafb705ad3abe779166921d6d2245a1a1d754ca2f696544d7f3e0ffef3a2813b0cd2b4716642875a72d7c9f1d699ac0b
ep_bytes: 558bec6aff6830f5460068c89e460064
timestamp: 2020-05-20 15:58:37

Version Info:

0: [No Data]

Zusy.305076 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen9.22670
MicroWorld-eScanGen:Variant.Zusy.305076
FireEyeGeneric.mg.a1db06964ddb2aa0
McAfeeGenericRXKQ-PL!A1DB06964DDB
CylanceUnsafe
SangforTrojan.Win32.Wacatac.D
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/ICLoader.881db9ec
K7GWTrojan ( 00588d921 )
K7AntiVirusTrojan ( 00588d921 )
CyrenW32/S-426c33ab!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HHUB
Paloaltogeneric.ml
ClamAVWin.Packed.Adrozek-9811562-0
KasperskyHEUR:Trojan.Win32.Ekstak.pef
BitDefenderGen:Variant.Zusy.305076
NANO-AntivirusTrojan.Win32.Ekstak.isgwsj
AvastWin32:AdwareX-gen [Adw]
EmsisoftGen:Variant.Zusy.305076 (B)
ComodoMalware@#2f5isbi4rtaxc
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXKQ-PL!A1DB06964DDB
SophosMal/Generic-R + Troj/Agent-BEQV
IkarusPUA.ICLoader
AviraHEUR/AGEN.1135761
Antiy-AVLTrojan/Generic.ASMalwS.3079588
MicrosoftBrowserModifier:Win32/Adrozek
GDataGen:Variant.Zusy.305076
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Tewgol.R337789
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Zusy.305076
MAXmalware (ai score=81)
MalwarebytesAdware.DownloadAssistant
APEXMalicious
RisingTrojan.Kryptik!1.AA23 (CLOUD)
SentinelOneStatic AI – Malicious PE
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareX-gen [Adw]
Cybereasonmalicious.64ddb2
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Zusy.305076?

Zusy.305076 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment