Malware

Zusy.312334 (B) malicious file

Malware Removal

The Zusy.312334 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.312334 (B) virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Zusy.312334 (B)?


File Info:

name: 4CD893234EC12F1B200B.mlw
path: /opt/CAPEv2/storage/binaries/131d790161d4dc46fe64ea4581f67305912f0c6b3017b5aa335c27395db4fdf0
crc32: 92E14109
md5: 4cd893234ec12f1b200b31dbdedce6ce
sha1: 0eea304f75774cd68fbeda32f8101e66b21ac3c3
sha256: 131d790161d4dc46fe64ea4581f67305912f0c6b3017b5aa335c27395db4fdf0
sha512: 0f7eda5c1280a59959f99bc41bf279db4db47b6701a80de1e177259c8b536d494bda5f651a1add0223a920c6dc3b22329a6c6939c284eda2a878d9b411524f64
ssdeep: 3072:MwV4OgSzBmh04eZFkz3Rr0BsGj9eqWf8:MMzzILGFkzhr0aGj9eqD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CEB3F1447F219E71C72D2D32A66BCE0403919D978C522B934A637E2FBEB35B74913D0A
sha3_384: be89d761c0a781159fc39ed1e3cafbee46a5c0031a1535b3bc9622b518bc96cf2bc67c206339d5eb10b280c40ef710de
ep_bytes: 60be1db043008dbee35ffcff57eb0b90
timestamp: 2065-04-05 03:16:26

Version Info:

0: [No Data]

Zusy.312334 (B) also known as:

Elasticmalicious (moderate confidence)
DrWebTrojan.MulDrop3.45645
MicroWorld-eScanGen:Variant.Zusy.312334
FireEyeGeneric.mg.4cd893234ec12f1b
CAT-QuickHealTrojan.Ramnit.A3
ALYacGen:Variant.Zusy.312334
CylanceUnsafe
ZillyaTrojan.PornoBlocker.Win32.2280
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0038b1be1 )
K7GWTrojan ( 0038b1be1 )
Cybereasonmalicious.34ec12
BitDefenderThetaGen:NN.ZexaF.34682.gmW@aaSKgujI
VirITTrojan.Win32.PornoBlocker.CLB
CyrenW32/Bamital.N.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Ramnit.AY
APEXMalicious
ClamAVWin.Virus.Lockscreen-56
KasperskyTrojan.Win32.Pakes.tyi
BitDefenderGen:Variant.Zusy.312334
NANO-AntivirusTrojan.Win32.Pakes.erqhzd
SUPERAntiSpywareTrojan.Agent/Gen-PornoBlocker
Ad-AwareGen:Variant.Zusy.312334
TACHYONTrojan/W32.PornoBlocker.108032
SophosML/PE-A
ComodoTrojWare.Win32.Agent.kwsr@4miu7u
BaiduWin32.Trojan.Pakes.a
VIPREGen:Variant.Zusy.312334
TrendMicroTROJ_FAKEAV.SMUP
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.312334 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PornoBlocker.cbo
GoogleDetected
AviraW32/Sality.AB.2
Antiy-AVLTrojan/Generic.ASBOL.DCD
KingsoftWin32.Infected.Ramnit.sr.(kcloud)
MicrosoftTrojan:Win32/Ramnit.A
ViRobotTrojan.Win32.A.PornoBlocker.206336.A
GDataGen:Variant.Zusy.312334
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Bamital.R30214
Acronissuspicious
McAfeeW32/Ramnit.l
MAXmalware (ai score=89)
VBA32SScope.Trojan.CRP.13205
MalwarebytesTrojan.Agent
TrendMicro-HouseCallTROJ_FAKEAV.SMUP
RisingTrojan.Win32.Fednu.ueo (CLASSIC)
IkarusVirus.Win32.Ramnit
MaxSecureTrojan.Pakes.tyi
FortinetW32/Drooptroop.SMY!tr
AVGWin32:Ramnit-AN
AvastWin32:Ramnit-AN
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Zusy.312334 (B)?

Zusy.312334 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment