Malware

Zusy.360470 malicious file

Malware Removal

The Zusy.360470 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.360470 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine Zusy.360470?


File Info:

name: 8506AA029EA76D2126C2.mlw
path: /opt/CAPEv2/storage/binaries/a3cd0de1e15f44a1346b3ba13bcd7b16a08486ec77048c8c7fb7601c3d9f9582
crc32: AAA92CBA
md5: 8506aa029ea76d2126c27f22c2dd7a35
sha1: 46286b484532afd326d2b45072c12f3c31e60d7f
sha256: a3cd0de1e15f44a1346b3ba13bcd7b16a08486ec77048c8c7fb7601c3d9f9582
sha512: 3855361abf5f6728080a8733f9924b5353213e178140eb6c8f3dcf611dcbdddcc42accde2b11eaed5df8b801097f71204fef77eada441386fff88f1fd5fb40dd
ssdeep: 3072:b1AoKUOZqnUbDWpqZaZKPKDhr/zGciszMe2oQYxeVHkeuQyZw92:b1Ao9OAXH9iOzX2oQkzeuNu92
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T183046B1AB460E02DD0D242B17FA8E5946B517EF0E47424673EC12F061FB85EA8DA2F77
sha3_384: 811f0802f22b3f7b3a49c01465a01e9aa504b2d254b6e00ef1e6ebf100104e0e9daa9b4e008e04f391bcb39383080a7e
ep_bytes: e8932c0000e989feffff8bff558bec81
timestamp: 2012-02-14 16:12:40

Version Info:

0: [No Data]

Zusy.360470 also known as:

LionicTrojan.Win32.Mokes.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.360470
FireEyeGeneric.mg.8506aa029ea76d21
ALYacGen:Variant.Zusy.360470
CylanceUnsafe
SangforBackdoor.Win32.Mokes.pef
K7AntiVirusTrojan ( 0056d4961 )
AlibabaBackdoor:Win32/Mokes.689b490e
K7GWTrojan ( 0056d4961 )
Cybereasonmalicious.29ea76
BitDefenderThetaAI:Packer.354BBA351F
CyrenW32/Kryptik.DED.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.ACGU
TrendMicro-HouseCallTROJ_GEN.R002H0CB322
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.Win32.Mokes.pef
BitDefenderGen:Variant.Zusy.360470
NANO-AntivirusTrojan.Win32.Mokes.ilacuu
AvastWin32:Trojan-gen
TencentWin32.Backdoor.Mokes.Dxmk
EmsisoftGen:Variant.Zusy.360470 (B)
DrWebTrojan.Siggen11.60621
McAfee-GW-EditionArtemis!Trojan
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-S
APEXMalicious
JiangminBackdoor.Mokes.ddd
AviraTR/ATRAPS.Gen
MicrosoftRansom:Win32/StopCrypt!ml
ZoneAlarmHEUR:Backdoor.Win32.Mokes.pef
GDataGen:Variant.Zusy.360470
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R374762
McAfeeGenericRXAA-FA!8506AA029EA7
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.SmokeLoader.Generic
RisingTrojan.Injector!1.D328 (CLASSIC)
IkarusTrojan.Win32.Agent
FortinetW32/Agent.ACGU!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Zusy.360470?

Zusy.360470 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment