Malware

How to remove “Zusy.346725”?

Malware Removal

The Zusy.346725 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.346725 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup

How to determine Zusy.346725?


File Info:

name: 3AD1B0878A98E8985155.mlw
path: /opt/CAPEv2/storage/binaries/a62b8dd9afd1f8abe94f5abe1fa2aa4352e9c3f5cb706386b000c997fd2d2db4
crc32: AE99EB2D
md5: 3ad1b0878a98e8985155b9be6d012e3c
sha1: 4ed1dbe423f1a39c9dc2326ce5ea91cb6236095a
sha256: a62b8dd9afd1f8abe94f5abe1fa2aa4352e9c3f5cb706386b000c997fd2d2db4
sha512: f823b95d8c486d1649827f5e44edaf13cdb659753097c8c01121a72d485f760cbdaa8bc1f57f635173c80619dc39f1cac9ba7a37ae56f77970c47622b653a619
ssdeep: 3072:+CaoAs101Pol0xPTM7mRCAdJSSxPUkl3VqMQTCk/dN92sdNhavtrVdewnAx3wmVS:+qDAwl0xPTMiR9JSSxPUKadodHZTH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17AD4E6123226CC55F2D0D27691A587B5FA709B8528F2C903FABCBE1A7F70B534E6D109
sha3_384: 3d4f060c2261cd9e46b10d4a62ccebdac582565f5f822ed3f07533f899b12147a52c823151759979e9f3553a3302f3a5
ep_bytes: e85bc20300e8b0a9030033c0c3909090
timestamp: 2015-01-28 13:36:24

Version Info:

0: [No Data]

Zusy.346725 also known as:

LionicTrojan.Win32.Scar.tpzq
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.346725
FireEyeGeneric.mg.3ad1b0878a98e898
CAT-QuickHealTrojan.GenericPMF.S19447789
ALYacGen:Variant.Zusy.346725
CylanceUnsafe
VIPRETrojan.Win32.Agent.owd (v)
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Starter.ali2000005
K7GWPassword-Stealer ( 004b75691 )
K7AntiVirusPassword-Stealer ( 004b75691 )
BitDefenderThetaGen:NN.ZexaF.34182.MmY@aWYJS4g
VirITTrojan.Win32.Dnldr12.BUVO
CyrenW32/S-d780eecb!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/PSW.QQPass.OWD
BaiduWin32.Trojan-PSW.QQPass.af
TrendMicro-HouseCallTROJ_GEN.R002C0CAV22
ClamAVWin.Malware.Zusy-6804618-0
KasperskyTrojan.Win32.Scar.oetk
BitDefenderGen:Variant.Zusy.346725
NANO-AntivirusTrojan.Win32.DangerousObject.dnizrq
APEXMalicious
TencentTrojan.Win32.Scar.16000124
EmsisoftGen:Variant.Zusy.346725 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.DownLoader12.31656
ZillyaTrojan.QQPass.Win32.24502
TrendMicroTROJ_GEN.R002C0CAV22
McAfee-GW-EditionBehavesLike.Win32.Trickbot.jh
SophosML/PE-A + Troj/Agent-BCIH
IkarusTrojan.Vundo
JiangminTrojan/Generic.bbckw
AviraTR/Crypt.XPACK.Gen3
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.EE78EA
MicrosoftTrojan:Win32/QQPass
GDataWin32.Trojan.PSE.1B0NIJU
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Scar.R440449
McAfeeTrojan-FFZL!3AD1B0878A98
VBA32Trojan.Downloader
MalwarebytesTrojan.QQPass
AvastWin32:QQPass-WK [Trj]
RisingTrojan.Kryptik!1.B3E8 (CLOUD)
YandexTrojan.Scar!TATK9bs/IaY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/QQPass.WK!tr
AVGWin32:QQPass-WK [Trj]
Cybereasonmalicious.78a98e
PandaTrj/Genetic.gen

How to remove Zusy.346725?

Zusy.346725 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment