Malware

Zusy.305460 removal

Malware Removal

The Zusy.305460 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.305460 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Zusy.305460?


File Info:

crc32: D11D6A05
md5: 408d00f4b50287dcff2f66bfaadcd166
name: 408D00F4B50287DCFF2F66BFAADCD166.mlw
sha1: 05eaffc42e3c662beed4ab0097ce7451b21ed545
sha256: 84be8112fc21fe67cd4146cba122a0ffbd219067c8ef5fd6714396106ed8058a
sha512: 5cab7cccf2d9d6c25e8c9c8c336b254f20d17d58676beb6154ec555cd31b04f554a545f9899180bd0485f0eb982546f3ed1205aba50e14c2ffb6a4335177c588
ssdeep: 24576:p9FWg5VyeRps/kWL7P3V+XMwPxub9LeFDWMOuUI:pa8Vyj/kp8GUBLeIa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x4e94x884cx6563x4ebax3014yemao.vipx3015 x7248x6743x6240x6709
FileVersion: 1.1.1.0
CompanyName: x4e94x884cx6563x4ebax3014yemao.vipx3015
Comments: Bilibili VIP Nexonplug
ProductName: Bilibili VIP Nexonplug
ProductVersion: 1.1.1.0
FileDescription: Bilibili VIP Nexonplug
Translation: 0x0804 0x04b0

Zusy.305460 also known as:

BkavW32.AIDetectVM.malware1
K7AntiVirusTrojan ( 005246d51 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.305460
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 00013a151 )
Cybereasonmalicious.4b5028
CyrenW32/OnlineGames.HG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Zusy-6840460-0
BitDefenderGen:Variant.Zusy.305460
MicroWorld-eScanGen:Variant.Zusy.305460
Ad-AwareGen:Variant.Zusy.305460
SophosGeneric PUA AF (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaGen:NN.ZexaF.34670.1r0@aK1nZhab
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
FireEyeGeneric.mg.408d00f4b50287dc
EmsisoftGen:Variant.Zusy.305460 (B)
SentinelOneStatic AI – Malicious PE
Antiy-AVLGrayWare/Win32.FlyStudio.a
MicrosoftProgram:Win32/Vigram.A
ArcabitTrojan.Zusy.D4A934
AegisLabTrojan.Win32.Generic.lwTx
GDataGen:Variant.Zusy.305460
Acronissuspicious
McAfeeGenericRXAA-FA!408D00F4B502
MAXmalware (ai score=87)
VBA32BScope.Trojan.Downloader
MalwarebytesTrojan.MalPack.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R002H09L220
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.65CA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM07.1.484B.Malware.Gen

How to remove Zusy.305460?

Zusy.305460 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment