Malware

How to remove “Zusy.351317 (B)”?

Malware Removal

The Zusy.351317 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.351317 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Zusy.351317 (B)?


File Info:

name: 07D02ED258414203362F.mlw
path: /opt/CAPEv2/storage/binaries/3706be0291d8c29ba9a5d778bca52ac5bfcb0c8a19b051e400fd792973748e7f
crc32: 9C9E2F21
md5: 07d02ed258414203362fc8d5e03eccc2
sha1: 3fd239b63f82842cdc886fe904ae20409bb37a27
sha256: 3706be0291d8c29ba9a5d778bca52ac5bfcb0c8a19b051e400fd792973748e7f
sha512: 886a2eb724ab7de9ce2adabd74296c49932fc57bd7045dd1ae2dffa0a5eda65a18ee8bdacc833e3a10374ec89d4cd7087c65a626b8a5b7a03326ce75e03e9d95
ssdeep: 98304:L8HXqeDkiUYiP2AwXIy/pIPDOElKN2gQ6JrwC7x6EWP2i:LneYipVAwXHIbnV6SCYEri
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17D36335FAF720D6CC3D50CF2288B4FF9D74848213E9D1DF9A03F69B61A7425A06AD864
sha3_384: 47f5b24e633f50fdfd08d96eb25184a6cc2ecc6131d5941031f658ac8e1de03da6004b41c7675352407985a6ea4e6d28
ep_bytes: 6803138200e91100000043e90b000000
timestamp: 2013-06-28 14:45:44

Version Info:

0: [No Data]

Zusy.351317 (B) also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.351317
FireEyeGeneric.mg.07d02ed258414203
CylanceUnsafe
VIPREGen:Variant.Zusy.351317
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0052c8a31 )
BitDefenderGen:Variant.Zusy.351317
K7GWTrojan ( 0052c8a31 )
Cybereasonmalicious.258414
VirITTrojan.Win32.Agent.BWB
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Ransomware.Aicat-9862601-0
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
Ad-AwareGen:Variant.Zusy.351317
SophosML/PE-A
F-SecurePacked:W32/PeCan.A
McAfee-GW-EditionBehavesLike.Win32.Sivis.rc
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Zusy.351317 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.351317
ArcabitTrojan.Zusy.D55C55
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Unwanted/Win.GameHack.R497939
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34592.@BW@amlaebei
ALYacGen:Variant.Zusy.351317
MAXmalware (ai score=80)
VBA32BScope.Trojan.Click
MalwarebytesMalware.AI.3075149993
RisingTrojan.Generic@AI.90 (RDML:00fJE1punlMw1Z+uLaFCgA)
YandexTrojan.GenAsa!2Teq1CwFdrg
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Filecoder.FV!tr.ransom
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Zusy.351317 (B)?

Zusy.351317 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment