Malware

Zusy.30899 removal guide

Malware Removal

The Zusy.30899 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.30899 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Zusy.30899?


File Info:

name: 989894D55EE6FBD0D2A1.mlw
path: /opt/CAPEv2/storage/binaries/dfe1c15af30f4e3bcf3870dbd8459d6a1e3776fdc6ff0bdd146cba27d2574eac
crc32: 48598F5C
md5: 989894d55ee6fbd0d2a15d43fa1aca31
sha1: 86c250c3b71068de14216175d4764aa93e1c25e3
sha256: dfe1c15af30f4e3bcf3870dbd8459d6a1e3776fdc6ff0bdd146cba27d2574eac
sha512: 4c32a63302a7c71363b130787908cc5c11c557491d7a3c263dc04913d818082b33fdcaa3daee6b6e0845b07fbb0d46a943c23d517954e3ea8e4cf88222e2f836
ssdeep: 6144:MFOiYdugQX3YYEKPpN+2+a0fvmHZqqujIlAxsmktImid:MFOiYmnDrP/QXmHZXujYAxsmiid
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CC84AC23E94744B7F3FBABFD69E5623C5A078D26D60AE1B710D48CD89528713B930938
sha3_384: 4332a7b98e4e61d801f7159ec8c7feb5f39428681b5101fa9239d9b0e293a387f6a2bec44a7a5e65fb79870f8dccdf72
ep_bytes: 558bec892dacb34500e822fdffff5dc3
timestamp: 2012-12-13 07:50:16

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows TaskManager
FileVersion: 5.00.2137.1
InternalName: taskmgr
LegalCopyright: Copyright (C) Microsoft Corp. 1991-1999
OriginalFilename: taskmgr.exe
ProductName: Microsoft(R) Windows (R) 2000 Operating System
ProductVersion: 5.00.2137.1
Translation: 0x0409 0x04b0

Zusy.30899 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.2401
MicroWorld-eScanGen:Variant.Zusy.30899
FireEyeGeneric.mg.989894d55ee6fbd0
ALYacGen:Variant.Zusy.30899
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.98473
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040f02a1 )
AlibabaTrojanPSW:Win32/Kryptik.77e36d29
K7GWTrojan ( 0040f02a1 )
Cybereasonmalicious.55ee6f
BitDefenderThetaGen:NN.ZexaF.34182.xq2@aSKQKGoi
CyrenW32/Zbot.GQ.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.BKGR
TrendMicro-HouseCallTROJ_SIGEKAF.SM
Paloaltogeneric.ml
ClamAVWin.Spyware.Zbot-68955
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.30899
NANO-AntivirusTrojan.Win32.Zbot.befwun
AvastWin32:DangerousSig [Trj]
TencentWin32.Trojan.Falsesign.Huzg
EmsisoftGen:Variant.Zusy.30899 (B)
ComodoTrojWare.Win32.Kryptik.ARJD@4t2k3w
VIPRETrojan.Win32.FakeAlert.bns (v)
TrendMicroTROJ_SIGEKAF.SM
McAfee-GW-EditionPWS-Zbot.gen.aql
SophosMal/Generic-R + Troj/Zbot-DHN
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.dwvgi
WebrootW32.Infostealer.Zeus
AviraTR/Crypt.EPACK.Gen2
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.547661
KingsoftWin32.Troj.Zbot.gz.(kcloud)
MicrosoftPWS:Win32/Zbot
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Zusy.30899
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win32.Injector.R47014
McAfeePWS-Zbot.gen.aql
VBA32TScope.Malware-Cryptor.SB
APEXMalicious
RisingTrojan.Generic!8.C3 (CLOUD)
IkarusTrojan-PWS.Win32.Zbot
MaxSecureTrojan.Malware.4976946.susgen
FortinetW32/Zbot.APRF!tr
AVGWin32:DangerousSig [Trj]
PandaTrj/OCJ.D
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Zusy.30899?

Zusy.30899 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment