Malware

Should I remove “Zusy.320654 (B)”?

Malware Removal

The Zusy.320654 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.320654 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Zusy.320654 (B)?


File Info:

name: 92A91CBCB7B57E3B0AC7.mlw
path: /opt/CAPEv2/storage/binaries/f6eb17a3578b7b100d158fdff010a06e67acf7f329c5cc3cbcb4dd88513e7a23
crc32: 7CE57A79
md5: 92a91cbcb7b57e3b0ac70355a99eacca
sha1: d426c0403f370a374b7b6093a729b861aa6e1adc
sha256: f6eb17a3578b7b100d158fdff010a06e67acf7f329c5cc3cbcb4dd88513e7a23
sha512: db795656b7941890c4da2fe4af97885fbae11ca58a33ab4d9af258850e0380bd8852a24e81137ea59cc7bfb0e52b5175eb1a86573d6f8d845d916c2f4e80fa3f
ssdeep: 24576:z4ywI3srl+3ReTdccEqaEmu8RBQanwF0GVHpC5Oknkuhh:E9AGEqaEmVNW0iMoknkuh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T115759D12F3604810E3F455345437AA6D11707EABD72D98FB4E983DE61DB2EF09AA6F02
sha3_384: f0afd714b75de39160a2ef7be375d8eb419290ffff470c22ac17779cf4ac0d59616001a860ebc9a9402e54633f6f9384
ep_bytes: 558bec6aff687805470068dca6460064
timestamp: 2020-10-16 17:18:38

Version Info:

Comments: cd,ripper,burner,mp3,tag,editor,music,library,converter
CompanyName: Acoustica
FileDescription: Acoustica MP3 CD Burner
FileVersion: 4, 0, 7, 2
InternalName: Acoustica's MP3 CD Burner
LegalCopyright: Copyright © 2001-2009 Acoustica. All Rights Reserved
OriginalFilename: cdburner.exe
ProductName: Acoustica MP3 CD Burner
ProductVersion: 4, 0, 7, 2
Translation: 0x0409 0x04b0

Zusy.320654 (B) also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Staser.4!c
MicroWorld-eScanGen:Variant.Zusy.320654
FireEyeGeneric.mg.92a91cbcb7b57e3b
ALYacGen:Variant.Zusy.320654
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Staser.vho
K7AntiVirusTrojan ( 005821bc1 )
BitDefenderGen:Variant.Zusy.320654
K7GWTrojan ( 005821bc1 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaCO.34182.Kv0@aOKq9Hbj
CyrenW32/ICLoader.CK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HHUB
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Zusy-9784995-0
KasperskyHEUR:Trojan.Win32.Staser.vho
AlibabaTrojan:Win32/Staser.19aa590a
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
Ad-AwareGen:Variant.Zusy.320654
EmsisoftGen:Variant.Zusy.320654 (B)
DrWebTrojan.Siggen9.22670
ZillyaTrojan.Kryptik.Win32.3475309
TrendMicroTROJ_GEN.R007C0PIJ21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/Generic-R + Troj/Agent-BEQV
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Ekstak.blxh
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1138971
Antiy-AVLTrojan/Generic.ASMalwS.30F5F2D
MicrosoftBrowserModifier:Win32/Adrozek
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmHEUR:Trojan.Win32.Staser.vho
GDataGen:Variant.Zusy.320654
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Crypt.R353351
McAfeeGenericRXMO-PF!92A91CBCB7B5
VBA32BScope.Trojan.Staser
MalwarebytesAdware.DownloadAssistant
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R007C0PIJ21
TencentWin32.Trojan.Staser.Htcb
YandexTrojan.Staser!ylj255Ppnig
MAXmalware (ai score=85)
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareX-gen [Adw]
AvastWin32:AdwareX-gen [Adw]

How to remove Zusy.320654 (B)?

Zusy.320654 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment