Malware

About “Zusy.311869” infection

Malware Removal

The Zusy.311869 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.311869 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Scheduled file move on reboot detected
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Zusy.311869?


File Info:

name: 7BECD4B8D439809C0B63.mlw
path: /opt/CAPEv2/storage/binaries/08bbf3ed83483032b94eca936e94dc8451e96a14fe1b381d72cb4cf0ab3b4ffb
crc32: 2A797804
md5: 7becd4b8d439809c0b633d1f4be08abc
sha1: 9bc5dad3a40921e64bfeeeea55d1a1092ee176fb
sha256: 08bbf3ed83483032b94eca936e94dc8451e96a14fe1b381d72cb4cf0ab3b4ffb
sha512: 302251e1b51852c502c2092d2fea747154562483c2e195e3bac70f73b6fac7a0f708923ea272ddefd903a0cce6e25ed212254d3d1e913d6ea29471f4ab37b3e4
ssdeep: 49152:nncc+4S0L1P7gPyY+M4RX9O6Q1V/Rxpi4ncc+4S0L1P7gPVow0TZNjpvq84xpLy:nxcRxpi4xWZxpLy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13FA5193E7B8EA572CDA1077C4D8FE294E84AB6302C242D47F6E05F4C5E30585772A99B
sha3_384: 0b6dd2087585499eee422f81098982ec631046a9da73807a735cabe4533f95a4b448152f92ca626eccfd5ce814ecbca2
ep_bytes: 558bec83c4f05356b8d89e4e00e80acf
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName:
FileDescription:
FileVersion: 1.0.0.35
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Translation: 0x0416 0x04e4

Zusy.311869 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.7becd4b8d439809c
CAT-QuickHealTrojan.Dorv.9812
McAfeePWS-Banker.gen.ez
CylanceUnsafe
ZillyaTrojan.Agent.Win32.233269
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 00581d0b1 )
BitDefenderGen:Variant.Zusy.311869
K7GWSpyware ( 00588e1e1 )
Cybereasonmalicious.8d4398
CyrenW32/Banker.V.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Banker.WGA
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Netmail-9844910-0
KasperskyHEUR:Trojan.Win32.Agentb.gen
NANO-AntivirusTrojan.Win32.Agent.dmeth
MicroWorld-eScanGen:Variant.Zusy.311869
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareGen:Variant.Zusy.311869
EmsisoftGen:Variant.Zusy.311869 (B)
ComodoTrojWare.Win32.Spy.Banker.AVIS@8f3ohb
DrWebTrojan.DownLoader10.14519
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.BANKER.SMTH
McAfee-GW-EditionBehavesLike.Win32.PWSBanker.vh
SophosML/PE-A + Troj/Banker-GYO
GDataWin32.Trojan-Stealer.Banker.AK
JiangminTrojan/Banker.Agent.ask
AviraDR/Delphi.Gen
Antiy-AVLTrojan/Generic.ASMalwS.D7BC4
MicrosoftTrojan:Win32/Dorv.B!rfn
TACHYONTrojan/W32.DP-Agent.2115584
AhnLab-V3Trojan/Win32.Agent.C111753
Acronissuspicious
BitDefenderThetaGen:NN.ZelphiF.34294.bI3@augecBkG
ALYacGen:Variant.Zusy.311869
MAXmalware (ai score=89)
VBA32BScope.Trojan.Downloader
MalwarebytesTrojan.Banker
TrendMicro-HouseCallTrojanSpy.Win32.BANKER.SMTH
RisingTrojan.Generic@ML.100 (RDML:D9LVF2kk3mRDboquZcIISg)
YandexTrojan.PWS.Agent!eYiUw0DT2vM
SentinelOneStatic AI – Malicious PE
MaxSecureWin.MxResIcn.Heur.Gen
FortinetW32/Banker.WGA!tr
AVGWin32:Trojan-gen
PandaTrj/Banker.MNZ
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Zusy.311869?

Zusy.311869 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment