Malware

Should I remove “Zusy.363211”?

Malware Removal

The Zusy.363211 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.363211 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine Zusy.363211?


File Info:

name: FFD70D2BDC634B0970A6.mlw
path: /opt/CAPEv2/storage/binaries/aca0445a0830935488ee56bfea19c8bb1cee98fd719679686410d50059d0e0cb
crc32: 86B5E0AE
md5: ffd70d2bdc634b0970a6c7a91c9a32da
sha1: 898973305a0b83551cd2bc227a3e59ce1c684a21
sha256: aca0445a0830935488ee56bfea19c8bb1cee98fd719679686410d50059d0e0cb
sha512: 54733ee6ea4eb27beeb263262446fedd83ba086e4f2b0670880f07ed7062b18b229ac035e3b8e4650b92560418682bbd24c81969d6485ff5a82b882d3860d459
ssdeep: 3072:R1qCKUO0eEnRYG7iw0+FQyvyVM6zGciszMe2oQYxeVHkeuQyZwo9VS:vqC9O0eEn7VSCjOzX2oQkzeuNu7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T177143B1AF860E12DC8D541F17F98E295AE217EF0E47461133EC12F366A781EA4DA1F63
sha3_384: d298751abf7a18a0897ca97eeadc427dad3002dfa239831ecf6d5a0f4a94f7b2092d50aea427c6007a627d00b6d03229
ep_bytes: e8932c0000e989feffff8bff558bec81
timestamp: 2012-02-14 16:12:40

Version Info:

0: [No Data]

Zusy.363211 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen11.60621
MicroWorld-eScanGen:Variant.Zusy.363211
FireEyeGeneric.mg.ffd70d2bdc634b09
CylanceUnsafe
K7AntiVirusTrojan ( 005741a81 )
AlibabaBackdoor:Win32/Mokes.dfbb53d4
K7GWTrojan ( 005741a81 )
Cybereasonmalicious.bdc634
BitDefenderThetaAI:Packer.DB9F05B01F
CyrenW32/Kryptik.DED.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HHSZ
TrendMicro-HouseCallTROJ_GEN.R002H0CA822
KasperskyHEUR:Backdoor.Win32.Mokes.pef
BitDefenderGen:Variant.Zusy.363211
NANO-AntivirusTrojan.Win32.Mokes.ihpimy
AvastWin32:Trojan-gen
RisingTrojan.Kryptik!1.D2DE (CLASSIC)
Ad-AwareGen:Variant.Zusy.363211
EmsisoftGen:Variant.Zusy.363211 (B)
McAfee-GW-EditionArtemis!Trojan
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
JiangminBackdoor.Mokes.ddd
AviraHEUR/AGEN.1140988
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Zusy.363211
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R374762
VBA32BScope.Backdoor.Mokes
MalwarebytesTrojan.SmokeLoader.Generic
APEXMalicious
TencentWin32.Backdoor.Mokes.Eivf
MAXmalware (ai score=80)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.ACGU!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zusy.363211?

Zusy.363211 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment