Malware

Zusy.324159 (file analysis)

Malware Removal

The Zusy.324159 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.324159 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A named pipe was used for inter-process communication
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Zusy.324159?


File Info:

crc32: CBF150E3
md5: 8fbb7b44b6a3a5c10b7ec3ca73861635
name: upload_file
sha1: 438a6b16d2bb77b4cb9ae8b13a99dbc801128e20
sha256: b18158f4b0b344bc4a14d29a5fd2a3e21ec1d6d90adf84fae18c972871a99557
sha512: a9586c19a7da51311c0ab53fcb03bcd65ead3d81edb95b07bc2f3450447148a43a1d0ca2cd4ea5861ca142eae9067dff42f8bb0411c3d49fec6271ed93f9cea1
ssdeep: 3072:xHnwmtgt9SX0Qqmhxt5yjSbpERPaIUpEgkRrTLwciZuYSXQkec5ZQjx:xH9USX0c7k2CPfUpERT0SXQk1f
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.324159 also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.324159
CAT-QuickHealTrojan.Generic
McAfeeGenericRXHK-SS!8FBB7B44B6A3
CylanceUnsafe
VIPRETrojan.Win32.Upatre.qv (v)
AegisLabTrojan.Win32.Generic.4!c
K7AntiVirusTrojan ( 005475701 )
BitDefenderGen:Variant.Zusy.324159
K7GWTrojan ( 005475701 )
Cybereasonmalicious.4b6a3a
TrendMicroTrojanSpy.Win32.TRICKBOT.THJBFBO
CyrenW32/Trickbot.R.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/TrickBot.ddbe29bf
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentWin32.Trojan.Generic.Eflj
Ad-AwareGen:Variant.Zusy.324159
SophosMal/TrikBot-B
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Trick.46210
ZillyaTrojan.TrickBot.Win32.333
InvinceaMal/Generic-R + Mal/TrikBot-B
McAfee-GW-EditionBehavesLike.Win32.VirRansom.cc
FireEyeGeneric.mg.8fbb7b44b6a3a5c1
EmsisoftGen:Variant.Zusy.324159 (B)
IkarusTrojan-Banker.TrickBot
AviraTR/Crypt.XPACK.Gen
ArcabitTrojan.Zusy.D4F23F
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Occamy.C
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Generic.C2509327
Acronissuspicious
BitDefenderThetaAI:Packer.508943761F
ALYacGen:Variant.Zusy.324159
MAXmalware (ai score=80)
VBA32BScope.Trojan.Trick
MalwarebytesTrojan.Dropper
PandaTrj/CI.A
ESET-NOD32a variant of Win32/TrickBot.CJ
TrendMicro-HouseCallTrojanSpy.Win32.TRICKBOT.THJBFBO
RisingTrojan.Generic@ML.100 (RDML:eduR+ti1AY7t6CvzsSt65Q)
YandexTrojan.Agent!v+9dmJbdkdE
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Generic.AP.1C23DE!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM19.1.D3C9.Malware.Gen

How to remove Zusy.324159?

Zusy.324159 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment