Malware

Should I remove “Zusy.336300”?

Malware Removal

The Zusy.336300 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.336300 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Binary file triggered YARA rule
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Zusy.336300?


File Info:

name: E8147542E1EC186FC5C6.mlw
path: /opt/CAPEv2/storage/binaries/799ffe15a631555f224acffbf02497d1029232debd8564c53190c0b62048c7f6
crc32: 39E4B00E
md5: e8147542e1ec186fc5c6d004db856335
sha1: 745d2c3ab6b5c521365108bfbef21fde2aaa0756
sha256: 799ffe15a631555f224acffbf02497d1029232debd8564c53190c0b62048c7f6
sha512: 668cefe4d637b0e32d809609611655a05ad9a13e09c1f5498650845a7ca415f4dfa0e5cc917d1c219d25c265764f4bf03eb9cff32f06dbe0fe38b30388c21c26
ssdeep: 49152:soNLSoqqIpVd22XJDl4suKij7BqrGTFYpu:sASoq9pLhDyT8Gac
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E6752221F751DD72C3C601363561EB71A62DBA3C276F9173F7A52A0A7B302D2A629307
sha3_384: 82a2f69b7d8fec07732c89a03c32d54947fdf8e669e78b5721d2dfbb55cf821601e9e6e2041ad375f5b8eb4abf04d962
ep_bytes: e8e3feffff33c050505050e88a2a0000
timestamp: 2010-02-10 13:09:55

Version Info:

0: [No Data]

Zusy.336300 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.336300
FireEyeGeneric.mg.e8147542e1ec186f
SkyhighBehavesLike.Win32.Rootkit.tc
McAfeeDownloader-FUV!E8147542E1EC
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
K7GWTrojan ( 005057171 )
K7AntiVirusTrojan ( 005057171 )
VirITWin32.Virut.CI
SymantecW32.SillyDC
ESET-NOD32Win32/TrojanDownloader.Agent.QFO
APEXMalicious
CynetMalicious (score: 99)
KasperskyUDS:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Scar.bqesv
AvastWin32:Geral [Trj]
BaiduWin32.Backdoor.Agent.n
F-SecureWorm.WORM/Citeary.doua
DrWebTrojan.BrowseBan.565
VIPREGen:Variant.Zusy.336300
TrendMicroTROJ_GEN.R03BC0DDE24
SophosMal/Generic-S
IkarusWorm.Win32.Citeary
JiangminHeur:TrojanDownloader.Agent
VaristW32/KillAV.AI.gen!Eldorado
AviraWORM/Citeary.doua
Kingsoftmalware.kb.a.1000
ZoneAlarmUDS:Trojan.Win32.Generic
GDataWin32.Trojan-Downloader.Agent.AD
GoogleDetected
VBA32BScope.Trojan.BrowseBan
ALYacGen:Variant.Zusy.336300
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BC0DDE24
RisingWorm.Citeary!1.D87E (CLASSIC)
FortinetW32/Trojandownloader.QCV!tr
AVGWin32:Geral [Trj]
DeepInstinctMALICIOUS

How to remove Zusy.336300?

Zusy.336300 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment