Malware

Zusy.368949 removal tips

Malware Removal

The Zusy.368949 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.368949 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine Zusy.368949?


File Info:

name: 3F6D6161C06DCE5BEF89.mlw
path: /opt/CAPEv2/storage/binaries/06e4215f0ada1b9b385d7663c49866d05e5ecf1ad67646eb8d7ee17860057e05
crc32: 9D2ACF36
md5: 3f6d6161c06dce5bef89189e4ab55da7
sha1: 9979fa3cb9592852db59dedbdc187dfe06860e7c
sha256: 06e4215f0ada1b9b385d7663c49866d05e5ecf1ad67646eb8d7ee17860057e05
sha512: f73429c2cdd8c91d6aca94951d0a0a53ab2d89822af2c20a389b3bdf62905227a310ab4624ad67ce86b5de9f355edaa6a99c530448635f55b97caefdaaeb2664
ssdeep: 1536:gxvKpKZ6IwBu/aR7HbZytUcE075CXEFNfTuj2AQ+tMpOPsK4L4i55DxTKc9JhD36:gZ1gbAtL5LU2AdMpwYb52cgLM3wAOX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ACF36C19B8B0D01DC89211F93CA8E2859E247EF0D57C10437AC13B5B6EB16EACD65FA7
sha3_384: 65bf68a6647910ff5fe6f1a171354db6e94862ec40236b61dd32c90b0e432184918e93cb8ea47439e296f706a9352e87
ep_bytes: e8cf200000e978feffff8bff558bec8b
timestamp: 2017-03-01 01:20:20

Version Info:

0: [No Data]

Zusy.368949 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.368949
FireEyeGeneric.mg.3f6d6161c06dce5b
ALYacGen:Variant.Zusy.368949
CylanceUnsafe
Cybereasonmalicious.1c06dc
CyrenW32/Kryptik.DEF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ENTI
APEXMalicious
KasperskyHEUR:Backdoor.Win32.Mokes.vho
BitDefenderGen:Variant.Zusy.368949
AvastWin32:Trojan-gen
TencentWin32.Backdoor.Mokes.Lmvd
Ad-AwareGen:Variant.Zusy.368949
EmsisoftGen:Variant.Zusy.368949 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.368949
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Generic.ASMalwS.310A34D
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.R369564
McAfeeArtemis!3F6D6161C06D
MAXmalware (ai score=89)
VBA32BScope.Backdoor.Mokes
MalwarebytesTrojan.SmokeLoader.Generic
TrendMicro-HouseCallTROJ_GEN.R011H0CL821
RisingMalware.Heuristic!ET#87% (RDMK:cmRtazo/9dYuFX+A7NLUGCQgzfyS)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.ACGU!tr
BitDefenderThetaGen:NN.ZexaF.34084.juW@ayTbY1gi
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Zusy.368949?

Zusy.368949 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment