Malware

Zusy.313531 (file analysis)

Malware Removal

The Zusy.313531 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.313531 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup

How to determine Zusy.313531?


File Info:

name: 3AF08D44F111FA4ABD11.mlw
path: /opt/CAPEv2/storage/binaries/801e9abf8d98c9e10e6f3f50cb587285ef2dd45608d03cd2168a562083be7a02
crc32: 9DCF8FB2
md5: 3af08d44f111fa4abd117e0e3d5d2679
sha1: f7d3366320f27d7e91699f678fd9354eeb5575f3
sha256: 801e9abf8d98c9e10e6f3f50cb587285ef2dd45608d03cd2168a562083be7a02
sha512: a0dda712c42d6c7b5815e8cc1d587837883e7448352b6216783ea188f2dad54d24c44408680f27b131c33b0e3513fa1ffcad72759b71efbda5c045fbd8807b97
ssdeep: 768:j25oagvnOdITTB62OP3J4kO3MOXDT4sX5lrD:jYoDOdITrOP3CppfHJlrD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CD947D13B5E2C173C545413156F2CF5E9F3FA9311A715E43ABA4AB5E2D307A0EA2B243
sha3_384: 5320b6fb834dbb8927685e281196d46b5c086ee1eb801ab6ac76c43cfe99be9f1e630f40d115f6d71bcfb4ceaf6f4b08
ep_bytes: 558bec6aff6868814000686039400064
timestamp: 2020-04-13 06:18:45

Version Info:

0: [No Data]

Zusy.313531 also known as:

BkavW32.AIDetect.malware1
FireEyeGeneric.mg.3af08d44f111fa4a
McAfeeArtemis!3AF08D44F111
CylanceUnsafe
K7AntiVirusSpyware ( 0056da391 )
K7GWSpyware ( 0056da391 )
CrowdStrikewin/malicious_confidence_60% (W)
ESET-NOD32a variant of Win32/Spy.Agent.PYF
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Zusy.313531
MicroWorld-eScanGen:Variant.Zusy.313531
AvastWin32:SpywareX-gen [Trj]
Ad-AwareGen:Variant.Zusy.313531
EmsisoftGen:Variant.Zusy.313531 (B)
McAfee-GW-EditionBehavesLike.Win32.BadFile.gz
IkarusTrojan-Spy
GDataGen:Variant.Zusy.313531
JiangminTrojan.Foreign.cwj
AviraTR/Spy.Agent.zfjip
MAXmalware (ai score=83)
ArcabitTrojan.Zusy.D4C8BB
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
VBA32BScope.TrojanDownloader.Agent
ALYacGen:Variant.Zusy.313531
MalwarebytesTrojan.IStartSurf
RisingSpyware.Agent!8.C6 (TFE:dGZlOgHKo7+U5xU/Dw)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.PYF!tr.spy
BitDefenderThetaGen:NN.ZexaF.34114.zyW@a4Ru8qcb
AVGWin32:SpywareX-gen [Trj]
Cybereasonmalicious.4f111f

How to remove Zusy.313531?

Zusy.313531 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment