Malware

How to remove “Zusy.316873”?

Malware Removal

The Zusy.316873 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.316873 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Zusy.316873?


File Info:

name: BA791DA114450F35E548.mlw
path: /opt/CAPEv2/storage/binaries/ba7a0a98a1b19a4fed5bfad02f8ddf51419cbd7033ac1b76c2a11c6345476066
crc32: 4757B0A5
md5: ba791da114450f35e548d5458a9e4b4e
sha1: b21c330160d2f4a92eab5fd13f3e87261d037d3a
sha256: ba7a0a98a1b19a4fed5bfad02f8ddf51419cbd7033ac1b76c2a11c6345476066
sha512: 1b97a6cb686b06e78c078bea89c1daf692f0db1576734dddc4bd622e44098339f892d72c0eb0aad4d45481e7bad515570e6a23af67dcc257e82c6b002393a79f
ssdeep: 49152:0XCFg1V/0CTIvOUzGv4FGSXWsl6bsWaxT4474UlzqzqXKCUEwCJURb2Vv4Aij:0XFTsFzV86ZXKCUEwxb2VQAC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10E369E337389653ED1EE1E399927D214993FB6223A52CC5B6BF80D4C0E76640793BA07
sha3_384: 4041a7f9df2a990e71f2b2eb2a5f89896803f312d81a2ef2c0f215f917f80c445b2709b7e45ad5d68977852d2e37979f
ep_bytes: 558bec83c4f0535657b8bcd17300e839
timestamp: 2016-05-19 04:01:31

Version Info:

CompanyName: .CompanyName
FileVersion: 1.0.0.1205
InternalName: .InternalName
LegalCopyright: .LegalCopyright
LegalTrademarks: .LegalTrademarks
OriginalFilename: .OriginalFilename
ProductName: .ProductName
ProductVersion: 1.0.0.0
Comments: .Comments
Translation: 0x0409 0x04e4

Zusy.316873 also known as:

LionicAdware.Win32.Generic.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.316873
FireEyeGeneric.mg.ba791da114450f35
McAfeeArtemis!BA791DA11445
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 004efef41 )
BitDefenderGen:Variant.Zusy.316873
K7GWAdware ( 004efef41 )
Cybereasonmalicious.114450
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/DLBoost.HO potentially unwanted
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
AlibabaAdWare:Win32/DLBoost.81fc228d
Ad-AwareGen:Variant.Zusy.316873
EmsisoftGen:Variant.Zusy.316873 (B)
DrWebTrojan.InstallMonster.1507
ZillyaAdware.DLBoost.Win32.142
TrendMicroTROJ_GEN.R002C0OL421
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.th
SophosGeneric ML PUA (PUA)
JiangminAdWare.Generic.tbqn
AviraHEUR/AGEN.1136586
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.132C762
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataGen:Variant.Zusy.316873
CynetMalicious (score: 99)
VBA32BScope.Adware.InstallMonster
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0OL421
YandexRiskware.Agent!nDproxOibTo
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_97%
FortinetRiskware/DLBoost
AVGWin32:LoadMoney-AKS [Adw]
AvastWin32:LoadMoney-AKS [Adw]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Zusy.316873?

Zusy.316873 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment