Malware

Zusy.329027 information

Malware Removal

The Zusy.329027 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.329027 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Authenticode signature is invalid

How to determine Zusy.329027?


File Info:

name: 565E7882A51C5D4F60B3.mlw
path: /opt/CAPEv2/storage/binaries/606cb81c71a9b487a7e5175ed33146910c08f11d2fe61c0a6121561729c46854
crc32: 1190BBA2
md5: 565e7882a51c5d4f60b37b5a926b7cbb
sha1: 3fe77ba59b3e166275d2ceee2f473df60b203411
sha256: 606cb81c71a9b487a7e5175ed33146910c08f11d2fe61c0a6121561729c46854
sha512: 821e80bcfb537ad3d8196b752eab086880ad6c1eb9ff02f4e2db8ad5f8fdf10beb17432a05f1d5ae939e195d81e7681726a80f2c11ba3b001c9af09d4784e2b4
ssdeep: 12288:6d5ILrlU28xihbOCbyq8tXnAMZgPL/kJH3V9hnD+1:6d5ILrlU28YhbOCbyq8TZgPL/kJXV9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EEB42A13D252C4A6E02D1AF22D7B07B46DF8D6A295718DC7EBF08CF16E513B25BA610C
sha3_384: c457b8b953f1342a8e866b871315c5416cfc4c27e1a3df375463b284c7014dfb45d5a861d06680371965e5d4dd23047e
ep_bytes: 558bec6aff68180e450068b853440064
timestamp: 2019-06-03 06:20:26

Version Info:

0: [No Data]

Zusy.329027 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Mikey.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.329027
FireEyeGeneric.mg.565e7882a51c5d4f
ALYacGen:Variant.Zusy.329027
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaBackdoor:Win32/BlackMoon.3a09b5a7
Cybereasonmalicious.2a51c5
BitDefenderThetaGen:NN.ZexaF.34182.FmW@aWEos@b
CyrenW32/BlackMoon.J.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
Paloaltogeneric.ml
ClamAVWin.Dropper.Tiggre-9845940-0
KasperskyBackdoor.Win32.Poison.jkgv
BitDefenderGen:Variant.Zusy.329027
NANO-AntivirusTrojan.Win32.Mikey.fqxiqe
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b5e214
EmsisoftGen:Variant.Zusy.329027 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
SentinelOneStatic AI – Malicious PE
SophosBlackMoon Packed (PUA)
APEXMalicious
AviraTR/Downloader.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2BBD430
MicrosoftPUA:Win32/Vigua.A
ZoneAlarmBackdoor.Win32.Poison.jkgv
GDataGen:Variant.Zusy.329027
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R266898
McAfeeGenericRXDP-AQ!565E7882A51C
MAXmalware (ai score=94)
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.648855877
RisingTrojan.Kryptik!1.B3E8 (CLOUD)
YandexTrojan.GenAsa!H8PaDbIDdIM
IkarusPUA.BlackMoon
MaxSecureTrojan.Malware.12240702.susgen
FortinetW32/CoinMiner.WP!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Zusy.329027?

Zusy.329027 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment