Malware

Zusy.334057 malicious file

Malware Removal

The Zusy.334057 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.334057 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with Themida
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine Zusy.334057?


File Info:

name: 52802D6CC9AB4169C64E.mlw
path: /opt/CAPEv2/storage/binaries/e12dd43415a4b237b0a6d5d4a7e9fcd387ce4dadd0fe4111bd4afbb0044c1138
crc32: 5C1DDBBF
md5: 52802d6cc9ab4169c64eac5eaf9cda1d
sha1: 824d585f343f8a587a2d15ff5a36d46bc625dae4
sha256: e12dd43415a4b237b0a6d5d4a7e9fcd387ce4dadd0fe4111bd4afbb0044c1138
sha512: 8678a758a6cd515d78678c6918052d097f465c192e9ed6736f6be90a838d55c9428d9957be9a2d46bbe3041ec63efc16f9f0312f5f4c1c1a21376ca981db71e3
ssdeep: 49152:PSjzDRgN3Ke07zR60RorKYeXMthzkCs15wOJdzW17QSiNG8OAOVzzCfsQzh9S:6jXR1LosLXOhps7EiNGjVzzCPtQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E9E5333E1F3476B6D01A9AF65473981080047D74D66A2FB51CCFF0F8217A6AA37AE478
sha3_384: 7968b7f2df74f37c85b611d2a386b560b905c4eb55be34bbdc7fa9c00fc48205c3bda787af694b3984f53bdbe6332645
ep_bytes: e84b0100005389e3538b73088b7b10fc
timestamp: 2020-11-23 11:14:16

Version Info:

0: [No Data]

Zusy.334057 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zusy.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.334057
FireEyeGeneric.mg.52802d6cc9ab4169
McAfeeArtemis!52802D6CC9AB
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/CrypterX.6a45e0c6
K7GWTrojan ( 0040f5a71 )
K7AntiVirusTrojan ( 0040f5a71 )
BitDefenderThetaAI:Packer.10AF94DA1F
SymantecML.Attribute.HighConfidence
AvastWin32:CrypterX-gen [Trj]
BitDefenderGen:Variant.Zusy.334057
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
EmsisoftGen:Variant.Zusy.334057 (B)
Paloaltogeneric.ml
AviraTR/Crypt.XPACK.Gen
MicrosoftVirTool:MSIL/CryptInject
GDataGen:Variant.Zusy.334057
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Wacatac.R361478
ALYacGen:Variant.Zusy.334057
MAXmalware (ai score=83)
VBA32BScope.TrojanPSW.Racealer
APEXMalicious
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazoqyWLUgxR92PZarbi0z5Oo)
SentinelOneStatic AI – Malicious PE
AVGWin32:CrypterX-gen [Trj]
Cybereasonmalicious.cc9ab4

How to remove Zusy.334057?

Zusy.334057 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment