Malware

Zusy.310301 removal instruction

Malware Removal

The Zusy.310301 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.310301 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Authenticode signature is invalid

How to determine Zusy.310301?


File Info:

name: B1558F2869A20BBC745E.mlw
path: /opt/CAPEv2/storage/binaries/a49449ce3880d2c97b1d82b3425fc7fe81655f863653e76421151b0e02d468f1
crc32: DA119686
md5: b1558f2869a20bbc745e3b8e1b7538fd
sha1: dd01301ebd94638bb59d3a37651bcac348e64892
sha256: a49449ce3880d2c97b1d82b3425fc7fe81655f863653e76421151b0e02d468f1
sha512: 23dd8dc358dcb8b562e6790ddd536f94fe5bc14c17d897de64a2167d6366671aab13222d58091e5b6003055fc35d5c1a1e247b0dd3241f7afe0cce410036a709
ssdeep: 3072:IxUrFPyhsu4K3vq9ogHOboRAuTxfFgrTUVSOp:XrUaIvc6LuTxLSOp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18BA37C41B5C1D831E5B21A3245A49A704A2EF9714FA18EEB7398067B4F301D1DB3ADBF
sha3_384: 5415f575fe9cf3b0b43bb313be83c1dd54c4a926367687776b35bc40e4a3fd79e2637f88a090da779d7abe7cd565048d
ep_bytes: e828060000e97afeffff558bec6a00ff
timestamp: 2020-07-30 12:06:44

Version Info:

0: [No Data]

Zusy.310301 also known as:

LionicTrojan.Win32.Zusy.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.310301
FireEyeGeneric.mg.b1558f2869a20bbc
McAfeeTrojan-FSUS!B1558F2869A2
CylanceUnsafe
ZillyaTrojan.BazarLoader.Win32.213
SangforTrojan.Win32.Skeeyah.A
K7AntiVirusTrojan ( 0057ab661 )
AlibabaTrojan:Win32/BazarLoader.b0534062
K7GWTrojan ( 0057ab661 )
Cybereasonmalicious.869a20
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/BazarLoader.R
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.BazarLoader-9861103-1
BitDefenderGen:Variant.Zusy.310301
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Zusy.310301
SophosMal/Generic-S + Troj/Bazar-N
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionTrojan-FSUS!B1558F2869A2
EmsisoftGen:Variant.Zusy.310301 (B)
IkarusTrojan-Downloader.Win32.Agent
GDataGen:Variant.Zusy.310301
AviraHEUR/AGEN.1142228
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Skeeyah.A!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.FSUS.R420966
VBA32BScope.Trojan.Mansabo
ALYacGen:Variant.Zusy.310301
YandexTrojan.BazarLoader!xzRU05MTCl8
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_95%
FortinetW32/Agent.UGT!tr
BitDefenderThetaGen:NN.ZexaF.34084.guW@au7@itbi
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Zusy.310301?

Zusy.310301 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment