Malware

About “Zusy.306545” infection

Malware Removal

The Zusy.306545 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.306545 virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.306545?


File Info:

name: AE8B484C48CA8728DE71.mlw
path: /opt/CAPEv2/storage/binaries/9dca936011f2d427c1fb111d168b8c92d6b5def6a71aeae651bc0aee9762eb6e
crc32: A671A6B4
md5: ae8b484c48ca8728de71385d16dddb11
sha1: a898eece98c3613d7635d8ae12ef23fcd9c3496f
sha256: 9dca936011f2d427c1fb111d168b8c92d6b5def6a71aeae651bc0aee9762eb6e
sha512: 35723b3d5c997b7b7d91ac3005e04a5235bdd349a475591820f8a0a1f38608180347395eea4bc8264f5eac078fbea5af8b91748ff1c69023f279700705b0aac1
ssdeep: 6144:/vPBvEQR6H3Udg2FuHRfepwqHpA7b2+yO2COKCZG:/vpv/R6H3U25fehHpAW+yOBOKCZG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F7A4A61372319491E1195BFBA7BA433879F8836438B0CD23EBE4DD62BDB5122971A70D
sha3_384: d834747ae60a8e3557d925f0273ea8a53f6c075720dd878b6e1ce36bb21cbd0a0e590d403ea07e81ee797efed6c46dda
ep_bytes: e83bbe0400e89aa3040033c0c3909090
timestamp: 2015-02-09 13:26:24

Version Info:

0: [No Data]

Zusy.306545 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.306545
ClamAVWin.Dropper.Tiggre-9845940-0
CAT-QuickHealRisktool.Flystudio.17330
McAfeePWS-FCCD!AE8B484C48CA
MalwarebytesGeneric.Trojan.Malicious.DDS
ZillyaTrojan.Scar.Win32.93505
SangforTrojan.Win32.Save.BlackMoon
K7AntiVirusPassword-Stealer ( 004b6c701 )
K7GWPassword-Stealer ( 004b6c701 )
Cybereasonmalicious.c48ca8
BaiduWin32.Trojan-PSW.QQPass.ag
CyrenW32/S-9853c063!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.QQPass.OVQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Scar.iizt
BitDefenderGen:Variant.Zusy.306545
NANO-AntivirusTrojan.Win32.Scar.dnsiov
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Malware-gen
TencentTrojan.Win32.Scar.xi
EmsisoftGen:Variant.Zusy.306545 (B)
F-SecureAdware.ADWARE/Adware.Gen
DrWebTrojan.DownLoader12.34053
VIPREGen:Variant.Zusy.306545
McAfee-GW-EditionBehavesLike.Win32.Generic.gm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.ae8b484c48ca8728
SophosTroj/Agent-BBAC
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.18PVCNI
JiangminTrojan/Scar.beau
AviraADWARE/Adware.Gen
MAXmalware (ai score=89)
Antiy-AVLVirus/Win32.Expiro.imp
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Zusy.D4AD71
ZoneAlarmTrojan.Win32.Scar.iizt
MicrosoftPWS:Win32/QQpass.B!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.Stealer.R143066
BitDefenderThetaGen:NN.ZexaF.36196.CqX@a0lJSM
ALYacGen:Variant.Zusy.306545
VBA32BScope.Trojan.StartPage
Cylanceunsafe
PandaTrj/Genetic.gen
RisingStealer.QQPass!1.9FF2 (CLASSIC)
IkarusTrojan-PSW.QQpass
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zusy.307491!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Zusy.306545?

Zusy.306545 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment