Malware

Zusy.308589 removal tips

Malware Removal

The Zusy.308589 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.308589 virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Binary file triggered multiple YARA rules
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Zusy.308589?


File Info:

name: 07CE6F623C3A2798803C.mlw
path: /opt/CAPEv2/storage/binaries/306472a1afda4f431899056a0e6535e9c7fb37490a4e992a8f50513e50beeb4d
crc32: 1590DB08
md5: 07ce6f623c3a2798803c84b6a7ab358e
sha1: a3852eabab1fa45394eda5fe3d5464ad2e1e240e
sha256: 306472a1afda4f431899056a0e6535e9c7fb37490a4e992a8f50513e50beeb4d
sha512: 2a2d0f010047a6834cc0c71d5884578ec0b96676b0aa65571df262dc92b8c99a90e2088ebc2d4f6f92f3e8bcc9a22440a77eeccdc72dff12cf3a6542365b0383
ssdeep: 24576:zbStlB+gAmg5pFwUT2Jc1CgWf5zQyUpkUhq:zSldgx2Jcy4/hq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D1459D12F641C0F5D70E167056793B3EEA7587925A30CA83D7A4EDB5AC331A1E33B24A
sha3_384: 33cb0cc3a9a8ca60ff6324a0950688581abcbe4fd6b223bed1b25244000fa701aad54402468c9846e3f007cc88228122
ep_bytes: 558bec6aff6850e24100683cd6400064
timestamp: 2019-10-24 05:20:39

Version Info:

0: [No Data]

Zusy.308589 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Midie.4!c
AVGWin32:FileinfectorX-gen [Trj]
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.308589
CAT-QuickHealTrojan.Generic.2919
SkyhighBehavesLike.Win32.Generic.th
McAfeeGenericRXAA-AA!07CE6F623C3A
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Zusy.308589
SangforTrojan.Win32.Save.BlackMoon
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.36802.lnX@aGHgYtk
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.BlackMoon.A suspicious
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Dropper.Tiggre-9845940-0
BitDefenderGen:Variant.Zusy.308589
NANO-AntivirusTrojan.Win32.Mikey.gghwne
AvastWin32:FileinfectorX-gen [Trj]
TencentMalware.Win32.Gencirc.10b4ce52
EmsisoftGen:Variant.Zusy.308589 (B)
F-SecureHeuristic.HEUR/AGEN.1345312
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.07ce6f623c3a2798
SophosBlackMoon Packed (PUA)
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraHEUR/AGEN.1345312
MAXmalware (ai score=81)
Antiy-AVLRiskWare/Win32.FlyStudio.a
MicrosoftTrojan:Win32/Wacatac.B!ml
XcitiumMalware@#30xjv26ofhlps
ArcabitTrojan.Zusy.D4B56D
GDataWin32.Trojan.Agent.WP
VaristW32/BlackMoon.J.gen!Eldorado
AhnLab-V3Trojan/Win.FPCQ.R480230
ALYacGen:Variant.Zusy.308589
VBA32BScope.Trojan.Occamy
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Generic@AI.98 (RDML:t/s41gTvv9p3ZENI/X6zrQ)
YandexTrojan.GenAsa!m9CKpdZ+MM0
IkarusTrojan-Spy.Win32.Agent
MaxSecureTrojan.Malware.12229157.susgen
FortinetW32/CoinMiner.ESFJ!tr
DeepInstinctMALICIOUS

How to remove Zusy.308589?

Zusy.308589 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment