Malware

Zusy.322466 (file analysis)

Malware Removal

The Zusy.322466 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.322466 virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to create or modify system certificates
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Zusy.322466?


File Info:

name: 76C315A6D01B048CA17E.mlw
path: /opt/CAPEv2/storage/binaries/db860e5f4bcec3411a7c45ea9148b2685644c26b44e92f4cd60629d3af0a960b
crc32: 870AB69B
md5: 76c315a6d01b048ca17e77bd19434210
sha1: 3031bda6d17bd9f994f5012239b5571ad9413da5
sha256: db860e5f4bcec3411a7c45ea9148b2685644c26b44e92f4cd60629d3af0a960b
sha512: a00bef5a2e303d3d8ba19fbf42cd734ddd08644e0724ae7f49d9e3e19ad216e88ab5c694a1693fc34ea4694b075ec26bb176bf8db920bea3a7367a45ac4630f6
ssdeep: 24576:FfR4X94KhxfQo1cbgjrkvz2M8JbaBS/04Nb88DtZDWXI+Wh+BuR:FfR4Xfhxb5UvyM8JGBS/04NzDO4dh+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EE064E5231E541AB8B3A32BC756F42A09E15381B135FBCA3B1E097B9D9F47BE4B94301
sha3_384: 614d204d93dbfc2e2a359c0eacc267a3ff2ed9921f16ad43e733d8a9fb9b24bfadb010d5172a2516ff403175db6e32f9
ep_bytes: e8f8640000e989feffff8bff558bec5d
timestamp: 2011-09-06 12:27:15

Version Info:

CompanyName: Solid State Networks
FileDescription: Adobe Flash Player Installer
FileVersion: 3.3.9.0
InternalName: host.exe
LegalCopyright: Copyright (C) Adobe Systems Incorporated
OriginalFilename: host.exe
ProductName: Adobe Flash Player Installer
ProductVersion: 3.3.9.0
Translation: 0x0409 0x04e4

Zusy.322466 also known as:

BkavW32.AIDetectMalware
AVGWin32:Agent-AYZG [Cryp]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.322466
FireEyeGeneric.mg.76c315a6d01b048c
SkyhighBehavesLike.Win32.Generic.wh
McAfeeGenericR-KPW!76C315A6D01B
MalwarebytesWapomi.Virus.FileInfector.DDS
ZillyaDropper.Agent.Win32.279169
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0049c2301 )
K7GWTrojan ( 0049c2301 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36802.Rx0@am8mJZdi
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDropper.Agent.QQR
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Ulise-9768992-0
KasperskyHEUR:Backdoor.Win32.Salgorea.gen
BitDefenderGen:Variant.Zusy.322466
NANO-AntivirusTrojan.Win32.Graftor.etoats
AvastWin32:Agent-AYZG [Cryp]
TencentTrojan.Win32.Agent.xd
EmsisoftGen:Variant.Zusy.322466 (B)
BaiduWin32.Trojan-Dropper.Agent.ab
F-SecureHeuristic.HEUR/AGEN.1312668
DrWebTrojan.Siggen7.30988
VIPREGen:Variant.Zusy.322466
Trapminemalicious.high.ml.score
SophosTroj/Agent-BFWP
IkarusTrojan-Dropper.Agent
JiangminTrojan.Generic.eeetn
VaristW32/Zusy.BJ.gen!Eldorado
AviraHEUR/AGEN.1312668
Antiy-AVLTrojan[Backdoor]/Win32.Salgorea.gen
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Salgorea.C!dha
XcitiumApplication.Win32.Amonetize.NE@5te978
ArcabitTrojan.Zusy.D4EBA2
ZoneAlarmHEUR:Backdoor.Win32.Salgorea.gen
GDataWin32.Trojan.PSE.17X2ZP9
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R358041
VBA32BScope.TrojanDropper.Agent
ALYacGen:Variant.Zusy.322466
MAXmalware (ai score=85)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.[OceanLotus]Salgorea!1.C3DC (CLASSIC)
YandexTrojan.Strictor!H4AlkDR60AA
SentinelOneStatic AI – Malicious PE
FortinetW32/Upatre.0285!tr
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/Agent.ebc84fd6

How to remove Zusy.322466?

Zusy.322466 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment