Malware

Zusy.306545 (B) removal instruction

Malware Removal

The Zusy.306545 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.306545 (B) virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.306545 (B)?


File Info:

name: 42FE8663D7C606584089.mlw
path: /opt/CAPEv2/storage/binaries/610ca9197c595dcdd27af326a626805add3df7e778ad19eb9ff59908b4f8579e
crc32: 76543F8C
md5: 42fe8663d7c6065840890be3c15776ba
sha1: 795dd677bccfb1cf4c10a28414abc505574c8cb5
sha256: 610ca9197c595dcdd27af326a626805add3df7e778ad19eb9ff59908b4f8579e
sha512: 591fb72f92725da60b47bec4c2c64f1da8fc6cfb393e7991fed773ca22270a9c85caaeb026ebc67758c0eb5cc4accc54f8102806f05fd94c051b0b391c669c15
ssdeep: 6144:O3Y9ZiiPHYUiZurYbKlJjJAvrj9IfOorL1DKzSh:O3YDiiPHYUwb4JjJAvr4OorL1WzSh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C5A4B703B221D491E55857FB63EA433469B8836438F1CD23EBE4DD62BCB5522971EB0E
sha3_384: 6a0ac8a267a23927dc439592631d0a3f109dd3ba32e4d28bd6749ea7d102f79ad66261cdeee35b48d0cd220f82df4a76
ep_bytes: e85b930400e8b878040033c0c3909090
timestamp: 2015-02-01 11:29:14

Version Info:

0: [No Data]

Zusy.306545 (B) also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.DownLoader15.50965
MicroWorld-eScanGen:Variant.Zusy.306545
FireEyeGeneric.mg.42fe8663d7c60658
CAT-QuickHealRisktool.Flystudio.17330
ALYacGen:Variant.Zusy.306545
MalwarebytesGeneric.Trojan.Malicious.DDS
VIPREGen:Variant.Zusy.306545
SangforTrojan.Win32.Save.BlackMoon
K7AntiVirusPassword-Stealer ( 004e83aa1 )
K7GWPassword-Stealer ( 004e83aa1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36196.BqY@ayHcCEl
CyrenW32/S-9853c063!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.QQPass.OUO
APEXMalicious
ClamAVWin.Dropper.Tiggre-9845940-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.306545
NANO-AntivirusTrojan.Win32.Scar.dvlkxz
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Trojan-gen
TencentTrojan.Win32.Qqpass.16000300
EmsisoftGen:Variant.Zusy.306545 (B)
F-SecureAdware.ADWARE/Adware.Gen
BaiduWin32.Trojan-PSW.QQPass.ag
ZillyaTrojan.QQPass.Win32.63006
McAfee-GW-EditionBehavesLike.Win32.Generic.gm
Trapminemalicious.high.ml.score
SophosTroj/Agent-BBAC
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.18PVCNI
JiangminTrojan/Scar.blwu
GoogleDetected
AviraADWARE/Adware.Gen
Antiy-AVLVirus/Win32.Expiro.imp
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Zusy.D4AD71
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/QQpass.B!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Stealer.R143066
McAfeePWS-FCCD!42FE8663D7C6
MAXmalware (ai score=88)
VBA32BScope.Trojan.StartPage
Cylanceunsafe
PandaTrj/Genetic.gen
RisingStealer.QQPass!1.9FF2 (CLASSIC)
YandexTrojan.Agent!+P6y2btwM2o
IkarusTrojan-PSW.QQpass
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zusy.307491!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.3d7c60
DeepInstinctMALICIOUS

How to remove Zusy.306545 (B)?

Zusy.306545 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment