Malware

Zusy.364955 (file analysis)

Malware Removal

The Zusy.364955 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.364955 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Zusy.364955?


File Info:

name: 638DFC812131CAE1D970.mlw
path: /opt/CAPEv2/storage/binaries/76eb65851d84f071be6bfcfa024f21127fa1b508a3abad16e99ccf72a3f42864
crc32: 459935BA
md5: 638dfc812131cae1d97063024a843806
sha1: c7dd4507d134ffdc09215fd0de38b8ffd683862c
sha256: 76eb65851d84f071be6bfcfa024f21127fa1b508a3abad16e99ccf72a3f42864
sha512: 84a7dc845315f188a8859d84a59b851028050eeaddb79f685b840bb58f63532935a3dabadad71879025f391bb5968e07f9598e58fcda9abc5b8f336905dff960
ssdeep: 49152:+BqjSDBrGBSkPbyp6ano1RYsj4Eh5SLiK9pddoPZ50m:djSDBrGEkP2p6FYskEhijdkYm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T196D5AE33B111D091D4551BFBA1A147382EB49B696CB5C853EBE0EDB2BC716329B0F70A
sha3_384: a36f2a84bb3e45814833b81b1cef1ed7ce6a065c0fdeb19e5701e1987cf385f060d8f8257f117bcd83821f8a33a5f833
ep_bytes: 558bec6aff68881d500068a88a4d0064
timestamp: 2020-03-27 05:24:35

Version Info:

0: [No Data]

Zusy.364955 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.364955
FireEyeGeneric.mg.638dfc812131cae1
McAfeeGenericRXAA-AA!638DFC812131
CylanceUnsafe
ZillyaTrojan.Blamon.Win32.1543
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005328801 )
K7GWTrojan ( 005328801 )
CrowdStrikewin/malicious_confidence_80% (D)
CyrenW32/Trojan.MKRE-6032
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
APEXMalicious
ClamAVWin.Dropper.Tiggre-9845940-0
KasperskyHEUR:Trojan.Win32.Blamon.vho
BitDefenderGen:Variant.Zusy.364955
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10b9d29b
Ad-AwareGen:Variant.Zusy.364955
EmsisoftGen:Variant.Zusy.364955 (B)
ComodoApplication.Win32.BlackMoon.AH@820q1i
DrWebTrojan.BtcMine.2446
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.364955
JiangminTrojan.Blamon.gy
eGambitUnsafe.AI_Score_100%
AviraHEUR/AGEN.1105983
Antiy-AVLTrojan/Win32.Blamon
ArcabitTrojan.Zusy.D5919B
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C1996770
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34084.QsW@amT5Gkgb
ALYacGen:Variant.Zusy.364955
MAXmalware (ai score=88)
VBA32BScope.Trojan.Yakes
MalwarebytesMalware.AI.791022476
RisingTrojan.Kryptik!1.B3E8 (CLASSIC)
IkarusPUA.BlackMoon
MaxSecureTrojan.Malware.74655505.susgen
FortinetW32/Tonmye.A!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.12131c
PandaTrj/Genetic.gen

How to remove Zusy.364955?

Zusy.364955 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment