Malware

About “Zusy.347379” infection

Malware Removal

The Zusy.347379 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.347379 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Turkish
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Operates on local firewall’s policies and settings
  • Anomalous binary characteristics

How to determine Zusy.347379?


File Info:

name: C62BBDEA21D63203608F.mlw
path: /opt/CAPEv2/storage/binaries/9a1997133ca2c8ab4b3cb0ce7482a22d35ffd606c1ecb3ca7a8c75c0510a8049
crc32: 5839D686
md5: c62bbdea21d63203608fab9e7e10949a
sha1: a40f84ec9f98dffd28a4ab07fd333c7551a914a3
sha256: 9a1997133ca2c8ab4b3cb0ce7482a22d35ffd606c1ecb3ca7a8c75c0510a8049
sha512: c2e00b6131dec451d4a594a932ce918fd9ae773972dd8db197527fc94df53ebfed18789413abf91d2db089965497779fe0e8471f726123edbf4901f3bd14eba3
ssdeep: 1536:+Z/fgkAqJlV+n1EgGHo7P1YPx28VHyonAsJGCnjaK:+1gkZl0nt/P1YPxEonJZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T130547B20F740C02EE4E102FEC5A68B76BA685F316B6444E3D3E1B6DD66752F27A3054B
sha3_384: 1226e0dc7794986da5ddfcd861580e6f5f302b7e50ca26ceab655d9567c37f3fe47cc6608690675d2be7169d867fdca9
ep_bytes: 558bec6aff68d07842006894a8400064
timestamp: 2012-02-16 13:40:02

Version Info:

Comments:
CompanyName:
FileDescription:
FileVersion: 6.0.150.3
InternalName: jusched
LegalCopyright: Copyright © 2011
LegalTrademarks:
OriginalFilename: jusched
PrivateBuild: Sun Microsystems, Inc.
ProductName: Java(TM) Platform SE 6 U15
ProductVersion: 6.0.150.3
SpecialBuild:
Translation: 0x0000 0x04b0

Zusy.347379 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.347379
ClamAVWin.Trojan.BankerSpy-1
FireEyeGeneric.mg.c62bbdea21d63203
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeW32/Autorun.worm.aacd
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Zusy.347379
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0022f6c71 )
K7GWTrojan ( 0022f6c71 )
Cybereasonmalicious.a21d63
BaiduWin32.Trojan.Agent.dc
VirITTrojan.Win32.Agent3.BHYJ
CyrenW32/Agent.KI.gen!Eldorado
SymantecW32.Griptolo
ESET-NOD32Win32/Agent.UDI
ZonerTrojan.Win32.77575
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Juched.fih
BitDefenderGen:Variant.Zusy.347379
NANO-AntivirusTrojan.Win32.Juched.fzczmn
SUPERAntiSpywareTrojan.Agent/Gen-Ganel
AvastWin32:Agent-APNJ [Trj]
TencentTrojan.Win32.FakeFolder.uu
SophosW32/Ganelp-D
F-SecureTrojan.TR/Graftor.1103.80
DrWebTrojan.Siggen3.48140
ZillyaTrojan.Agent.Win32.222584
TrendMicroWORM_GANELP.SMIA
McAfee-GW-EditionBehavesLike.Win32.Autorun.dz
EmsisoftGen:Variant.Zusy.347379 (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.14DQDNM
JiangminWorm/Generic.qfm
WebrootW32.Worm.Gen
AviraTR/Graftor.1103.80
Antiy-AVLWorm/Win32.Juched
XcitiumWorm.Win32.Juched.PGY@4yojo0
ArcabitTrojan.Zusy.D54CF3
ViRobotWorm.Win32.A.Juched.200704.A
ZoneAlarmWorm.Win32.Juched.fih
MicrosoftTrojan:Win32/Vindor!pz
GoogleDetected
AhnLab-V3Trojan/Win32.Npkon.R18258
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36662.ry3@aiIyySeG
ALYacGen:Variant.Zusy.347379
MAXmalware (ai score=82)
VBA32Worm.Juched
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallWORM_GANELP.SMIA
RisingTrojan.Agent!1.C135 (CLASSIC)
YandexTrojan.GenAsa!FgLooG3cvxI
IkarusTrojan.Win32.Webprefix
MaxSecureWorm.Win32.Juched.FIH
FortinetW32/Agent.SRG!tr
AVGWin32:Agent-APNJ [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zusy.347379?

Zusy.347379 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment