Malware

How to remove “Zusy.313842 (B)”?

Malware Removal

The Zusy.313842 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.313842 (B) virus can do?

  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Zusy.313842 (B)?


File Info:

name: 6404348A17F3D29990C4.mlw
path: /opt/CAPEv2/storage/binaries/339adbbd4dc5c7947de9daff3a1f6be120fddda84074a5db3498cb6910457ea3
crc32: 6DFBF831
md5: 6404348a17f3d29990c4f71bf4293e04
sha1: d0be77c2286003b98376ed931fd2cc3ff716a7b5
sha256: 339adbbd4dc5c7947de9daff3a1f6be120fddda84074a5db3498cb6910457ea3
sha512: 416435f8653288b6f14812050747c2c670a7f31a5c63ed0bcb26d9ae12825d759be87cff2f03cad0e6c3531b475537ca9825e76cc8a19017d1a477764ee66468
ssdeep: 49152:60c/mtFm7KFcSval7/J1YXn50KF4sN1vzbPUsx7cZRF77NvJeEL39AR5lz8XJK:99Bval7/3YWnMTF7ERFHe8NATlzUA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T113F5236527DAA285D5C6E7FDE3D1021288FCBAAF8262B6D96C547306B210F443B705F3
sha3_384: 80a38bc5174ba68e8385c18b5ffb0c7b43aa6ded45744a7e5dfce23026af62e3dc12ef8d3f06ff47830928b4e9b20a5e
ep_bytes: 558d6c249881ec0c02000056e9ae0300
timestamp: 2021-11-15 16:19:54

Version Info:

0: [No Data]

Zusy.313842 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.313842
FireEyeGeneric.mg.6404348a17f3d299
CAT-QuickHealTrojan.Wacatac.S15862760
McAfeeGenericRXIP-KU!6404348A17F3
K7AntiVirusTrojan ( 0056cc351 )
K7GWTrojan ( 0056cc351 )
Cybereasonmalicious.a17f3d
CyrenW32/Graftor.RC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GOGM
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.313842
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Evo-gen [Susp]
Ad-AwareGen:Variant.Zusy.313842
EmsisoftGen:Variant.Zusy.313842 (B)
DrWebTrojan.PackedENT.124
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SophosML/PE-A + Troj/AGent-BFHO
GDataGen:Variant.Zusy.313842
JiangminTrojan.Generic.hdrot
AviraTR/Crypt.EPACK.Gen2
Antiy-AVLTrojan/Generic.ASBOL.C639
ArcabitTrojan.Zusy.D4C9F2
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R346633
VBA32BScope.Trojan.PackedENT
ALYacGen:Variant.Zusy.313842
MAXmalware (ai score=85)
MalwarebytesTrojan.Crypt.Generic
RisingTrojan.Kryptik!1.BBF5 (CLASSIC)
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_100%
FortinetW32/Kryptik.GOGM!tr
BitDefenderThetaAI:Packer.7B7F8FFE1E
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Zusy.313842 (B)?

Zusy.313842 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment