Malware

Zusy.363577 (file analysis)

Malware Removal

The Zusy.363577 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.363577 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Possible date expiration check, exits too soon after checking local time
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • A scripting utility was executed
  • Executed a process and injected code into it, probably while unpacking
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

How to determine Zusy.363577?


File Info:

crc32: 53474C75
md5: 0cb6ce3e8ef55759fc557fec2875fe4c
name: 0CB6CE3E8EF55759FC557FEC2875FE4C.mlw
sha1: 7d3c4adabb64a6703d9a5f9380ebb6887c1930a3
sha256: 9a09b1b76bec24c1dc6b8a6e0b899e19425d8864918a5c2ad5011642c7f68533
sha512: 53f2523d7493f8c1150ad8ebe239f9b6ecc0ec63df604ea2aea0b0489976e7ffa8a2a6da234a664373d4c67b35ce1f6d1ce5d45addd773567b48cd2a99e0b7ac
ssdeep: 12288:ip+u0xvD//E0M+Vi8mWT00NI1BiYfc+EydwXmMcQNr7lhJd5:iAu0Zb/TMam+0xCmMcQNrDJd5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 1
FileVersion: 1.0.0.0
CompanyName: 1
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.dywt.com.cn)
ProductName: 1
ProductVersion: 1.0.0.0
FileDescription: 1
Translation: 0x0804 0x04b0

Zusy.363577 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005246d51 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Kilonepag.25975
ALYacGen:Variant.Zusy.363577
CylanceUnsafe
SangforWin.Malware.Zusy-6840460-0
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaMalware:Win32/Dorpal.ali1000029
K7GWPassword-Stealer ( 0049ad991 )
Cybereasonmalicious.e8ef55
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.Injector.D potentially unwanted
APEXMalicious
AvastFileRepMetagen [Malware]
ClamAVWin.Malware.Zusy-6840460-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.363577
MicroWorld-eScanGen:Variant.Zusy.363577
Ad-AwareGen:Variant.Zusy.363577
SophosMal/Generic-S
ComodoWorm.Win32.Dropper.RA@1qraug
BitDefenderThetaGen:NN.ZexaF.34608.2q0@aOr5x4pb
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
FireEyeGeneric.mg.0cb6ce3e8ef55759
EmsisoftGen:Variant.Zusy.363577 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
MicrosoftTrojan:Win32/Wacatac.B!ml
GridinsoftTrojan.Win32.Gen.bot!i
ArcabitTrojan.Zusy.D58C39
GDataWin32.Trojan.PSE.1U8NZ9I
Acronissuspicious
McAfeeRDN/Generic.hbg
MAXmalware (ai score=80)
MalwarebytesTrojan.MalPack.FlyStudio
RisingMalware.Heuristic!ET#98% (RDMK:cmRtazpR4ydz+keROB7EHRU9n+5W)
IkarusTrojan.Win32.MBRlock
FortinetW32/PossibleThreat
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml
Qihoo-360HEUR/QVM07.1.EE66.Malware.Gen

How to remove Zusy.363577?

Zusy.363577 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment