Malware

Zusy.367484 removal guide

Malware Removal

The Zusy.367484 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.367484 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine Zusy.367484?


File Info:

name: AFD34702C3B48DCAA3EE.mlw
path: /opt/CAPEv2/storage/binaries/10b6e4f2a02f41c236219449ffdd043aba02b343adc1f496c1a0b31cf6ebbd01
crc32: 9AAF083A
md5: afd34702c3b48dcaa3ee4498e6b20053
sha1: 477f83e90cc8560d9a319aeb0e0a7f2ca8511c4c
sha256: 10b6e4f2a02f41c236219449ffdd043aba02b343adc1f496c1a0b31cf6ebbd01
sha512: 01a090eb7a64579a8d39f73d674f2d0d79c2e200c5e7ede11dfbb6a0d880994bdcebd930e436c2b980bbf43fb29eec60ba648d8924b9a845777eb3356379039a
ssdeep: 3072:pQg5YKU+JkIwwq9pcqYcJQ04WoZlaBNFJ9CW:Cg5Y9+7qdJFoZ2a
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F2E35A18F420E019C8A196FA7D5CE9964964BAF0C1B920433EC33B579FB45ED89B6F43
sha3_384: 58994b99d94a55c208adfe995bb09c91ee96253aa496ff3995977ec96ad4b26447ab9ad3be7c0918cb535d0117b8712a
ep_bytes: e8932c0000e989feffff8bff558bec81
timestamp: 2012-02-14 16:12:40

Version Info:

0: [No Data]

Zusy.367484 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Mokes.m!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen11.60621
MicroWorld-eScanGen:Variant.Zusy.367484
FireEyeGeneric.mg.afd34702c3b48dca
ALYacGen:Variant.Zusy.367484
CylanceUnsafe
Cybereasonmalicious.2c3b48
BitDefenderThetaAI:Packer.DEE91D551F
CyrenW32/Kryptik.DFS.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.ACGU
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.Win32.Mokes.pef
BitDefenderGen:Variant.Zusy.367484
NANO-AntivirusTrojan.Win32.Mokes.ifisjx
AvastWin32:Trojan-gen
TencentWin32.Backdoor.Mokes.Lsbz
Ad-AwareGen:Variant.Zusy.367484
EmsisoftGen:Variant.Zusy.367484 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosMal/Generic-S
IkarusWin32.Outbreak
GDataGen:Variant.Zusy.367484
JiangminBackdoor.Mokes.ddd
AviraHEUR/AGEN.1140988
Antiy-AVLTrojan/Win32.Agent
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Zusy.D59B7C
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Smokeldr.R369422
Acronissuspicious
McAfeeRDN/Generic BackDoor
MAXmalware (ai score=83)
VBA32BScope.Backdoor.Mokes
RisingTrojan.Injector!1.D328 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.ACGU!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Zusy.367484?

Zusy.367484 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment