Malware

About “Zusy.307895” infection

Malware Removal

The Zusy.307895 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.307895 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Zusy.307895?


File Info:

crc32: D7FB0110
md5: 77b7ee62cc692b825283e3036ef8a8e4
name: sabix.exe
sha1: fa52096ed7b37a332792b037e72fd78d4664e400
sha256: 496915df405522ba15593a35d2c7d2da7adbe9dec2cfe62d2db4a47e81fddcca
sha512: ebaa4ee1d776a2e0e6ccb788507412158cc8856945671e34662587cf4bacef434e010380455f1e1f8674764893fd6d77f7c61818126e776055240c75ffebf2fe
ssdeep: 12288:bCbpcLhilrm7G8oclWEAroCo3DQmTj7prYQ3riwwhpMmm:MuLhi80Jro7FrYOrYzk
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.307895 also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Zusy.307895
FireEyeGeneric.mg.77b7ee62cc692b82
Qihoo-360HEUR/QVM05.1.571F.Malware.Gen
McAfeeFareit-FTB!77B7EE62CC69
K7AntiVirusTrojan ( 00569c031 )
BitDefenderGen:Variant.Zusy.307895
K7GWTrojan ( 00569c031 )
Cybereasonmalicious.ed7b37
Invinceaheuristic
F-ProtW32/Injector.ABY.gen!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Malware-gen
GDataGen:Variant.Zusy.307895
KasperskyHEUR:Trojan-Downloader.Win32.Adload.gen
RisingMalware.Heuristic!ET#83% (RDMK:cmRtazr4UVpjZv8Jwp/4JRqmC+qD)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Zusy.307895 (B)
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan.Inject
CyrenW32/Injector.ABY.gen!Eldorado
JiangminTrojanDownloader.Adload.aanr
MAXmalware (ai score=83)
Antiy-AVLTrojan[PSW]/Win32.Chisburg
ArcabitTrojan.Zusy.D4B2B7
ZoneAlarmHEUR:Trojan-Downloader.Win32.Adload.gen
MicrosoftTrojan:Win32/LokiBot.GA!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R342401
Acronissuspicious
VBA32TScope.Trojan.Delf
ALYacGen:Variant.Zusy.307895
Ad-AwareGen:Variant.Zusy.307895
MalwarebytesTrojan.MalPack.DLF
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EMNJ
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.ELXR!tr
BitDefenderThetaGen:NN.ZelphiF.34130.RGW@aKp2t9ci
AVGWin32:Malware-gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Zusy.307895?

Zusy.307895 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment