Malware

About “Zusy.320612” infection

Malware Removal

The Zusy.320612 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.320612 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Authenticode signature is invalid
  • Behavioural detection: Transacted Hollowing

How to determine Zusy.320612?


File Info:

name: 23273A83BFD7AED10B94.mlw
path: /opt/CAPEv2/storage/binaries/f6c62f9f846b3d100d60b1f2ae57a71c91dd8dc215dce652e2c85dff60c0197f
crc32: 5CF56F78
md5: 23273a83bfd7aed10b9403e23a8bcba9
sha1: 78d1c1e11ebae22849bccb3eb154ec986d992364
sha256: f6c62f9f846b3d100d60b1f2ae57a71c91dd8dc215dce652e2c85dff60c0197f
sha512: 279f1e6887adccb2d679736354b5df51c78e7308c05b47ae2dba66ec7d73e46ace8aa6ec33a2001cce7f6a20870ea3ea6acf4f49ca8f137aa11dddb26487ce90
ssdeep: 6144:/gLKYYoeCQEgGS0t1lem1qXAva/BeIHhAMMwXS:4rZeJEg+lHi9BeIHhAMMwXS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15F54AE1075C5C673F06306FC49B593B28E26FC618B31969F77E82FEE4E285C2A95431A
sha3_384: aea56e6cc1dfc9092a41ece3b96c8d5d6dcbab5f9f01701defe48b29bed87900b0b821d84c24ef7cef6dabd4b3fa5102
ep_bytes: e8b6560000e995feffffff35dca76100
timestamp: 2015-02-27 14:29:51

Version Info:

CompanyName: Symantec Corporation
LegalCopyright: Copyright© 1998-2008 Symantec Corporation, All rights reserved.
LegalTrademarks: Symantec?¡¢Symantec »Õ±ê¡¢Symantec Backup Exec? ºÍ Symantec NetBackup? ÊÇ Symantec Corporation µÄÉ̱ê»ò×¢²áÉ̱ꡣ
FileDescription: Symantec DLO Desktop Agent
FileVersion: 3.10.346.0601
OriginalFilename: ClientUI.exe
ProductName: Desktop and Laptop Option
ProductVersion: 3.01.00.0000
BuildNumber: 3.46.06a
Translation: 0x0804 0x04b0

Zusy.320612 also known as:

MicroWorld-eScanGen:Variant.Zusy.320612
FireEyeGeneric.mg.23273a83bfd7aed1
McAfeeGenericR-EJA!23273A83BFD7
CylanceUnsafe
VIPREGen:Variant.Zusy.320612
SangforTrojan.Win32.Save.a
K7AntiVirusPassword-Stealer ( 0055e3dc1 )
AlibabaTrojanPSW:Win32/CakeDuke.b970e029
K7GWPassword-Stealer ( 0055e3dc1 )
Cybereasonmalicious.3bfd7a
VirITTrojan.Win32.Dnldr13.CFFM
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/PSW.Agent.OAI
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.CakeDuke.a
BitDefenderGen:Variant.Zusy.320612
NANO-AntivirusTrojan.Win32.Agent.dqzsao
AvastWin32:Malware-gen
TencentWin32.Trojan.Cakeduke.Hnut
Ad-AwareGen:Variant.Zusy.320612
SophosTroj/Agent-AMVH
ComodoMalware@#3rgj9c35eo4j8
DrWebTrojan.DownLoader13.38674
ZillyaTrojan.Agent.Win32.528469
TrendMicroBKDR_COSMICDUKE.A
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dh
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.320612 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.320612
JiangminTrojan.CakeDuke.b
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1224191
Antiy-AVLTrojan/Generic.ASMalwS.4694
MicrosoftTrojan:Win32/Skeeyah.A!rfn
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Tinybaron.C859638
BitDefenderThetaGen:NN.ZexaF.34592.rq0@a8lOl4ji
ALYacGen:Variant.Zusy.320612
MAXmalware (ai score=100)
TrendMicro-HouseCallBKDR_COSMICDUKE.A
RisingTrojan.Generic@AI.100 (RDML:NZrvwJHOlMX4djHJfxtU+g)
YandexTrojan.PWS.Agent!4DCE+65NukE
IkarusTrojan.Win32.PSW
FortinetW32/Agent.OAI!tr.pws
AVGWin32:Malware-gen
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zusy.320612?

Zusy.320612 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment