Malware

Zusy.323205 (file analysis)

Malware Removal

The Zusy.323205 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.323205 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Creates a copy of itself

How to determine Zusy.323205?


File Info:

name: C0DAADFC82E5762FD1E4.mlw
path: /opt/CAPEv2/storage/binaries/01e61ed40cc51df776f2c3d3d85d1c6f8435026c2f1a6c1d9f8d1a29f4098c66
crc32: C2D50AAC
md5: c0daadfc82e5762fd1e412b1151ee2e5
sha1: 3517b4b0a6cbce7dc084dc286556624fb45ab9da
sha256: 01e61ed40cc51df776f2c3d3d85d1c6f8435026c2f1a6c1d9f8d1a29f4098c66
sha512: 3e944ba4f110c5df81dea52ad5827e85dce1bb916d26c2d85396437a73d6327f9abcefde2f1892b38de098dd5b0837cd7f0bb33b3ed9524fb448dd75d64c3af4
ssdeep: 49152:Pc5HY/vLrKak8NSSX+uhanmnsbdhalIyvLHylckqrXKP9osH8i:U547mak8NZdha3hMlfCqrXW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ADB5021362D50077D1F14E39CD27BDE57577BE22BE028C3866E8ACC92A296D1F207297
sha3_384: a1d1fe91c740bc6b2da83dcce9e2395e8dd266247c2f8ddd0583570190e05b1f7eab2b165e88dec2e10858f6d3d18966
ep_bytes: 558bec6aff68a8c6570068c0b6570064
timestamp: 2020-10-10 18:57:23

Version Info:

0: [No Data]

Zusy.323205 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Razy.a!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.323205
McAfeeArtemis!C0DAADFC82E5
MalwarebytesAdware.DownloadAssistant
Sangfor[ARMADILLO V1.71]
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderGen:Variant.Zusy.323205
K7GWTrojan ( 0058214e1 )
K7AntiVirusTrojan ( 0058214e1 )
CyrenW32/FakeAlert.FY.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HAYM
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Adrozek-9811562-0
KasperskyHEUR:Trojan-Downloader.Win32.Razy.vho
AlibabaTrojanDownloader:Win32/Kryptik.02e48246
TencentWin32.Trojan-downloader.Razy.Syhu
Ad-AwareGen:Variant.Zusy.323205
EmsisoftGen:Variant.Zusy.323205 (B)
F-SecureHeuristic.HEUR/AGEN.1244176
DrWebTrojan.PWS.Stealer.29366
BitDefenderThetaGen:NN.ZexaF.34606.uAW@aWODv4pk
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.c0daadfc82e5762f
SophosMal/Generic-R + Troj/Agent-BEQV
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Razy.hci
AviraHEUR/AGEN.1244176
MAXmalware (ai score=81)
MicrosoftBrowserModifier:Win32/Adrozek
ArcabitTrojan.Zusy.D4EE85
GDataGen:Variant.Zusy.323205
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Wacatac.R358619
Acronissuspicious
VBA32BScope.Trojan.CryptInject
ALYacGen:Variant.Zusy.323205
CylanceUnsafe
RisingTrojan.Kryptik!1.AA23 (CLOUD)
YandexTrojan.Kryptik!e6Rk1P0u2rc
IkarusTrojan.Crypt.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HASW!tr
AVGWin32:AdwareX-gen [Adw]
Cybereasonmalicious.c82e57
AvastWin32:AdwareX-gen [Adw]

How to remove Zusy.323205?

Zusy.323205 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment